Cybercriminals have developed a new sophisticated scheme targeting Web3 developers. In this campaign, attackers use fake job offers to lure victims into a trap on GitHub.

Scammers pose as recruiters on the LinkedIn platform. They contact developers with job offers and then direct them to GitHub repositories containing fake projects. Inside these repositories, malicious code is hidden—a Node.js loader cleverly disguised as a legitimate Tailwind CSS plugin.

Once a developer downloads and runs this code, the malware gains full control over the system. It can:

  • Steal personal data and files from the victim's computer.
  • Extract cryptocurrency wallet data, including seed phrases and private keys.
  • Execute remote commands, turning the computer into part of a botnet.
  • Monitor the clipboard, replacing wallet addresses during transactions.

This attack is particularly dangerous because it targets the professional community. Developers are accustomed to trusting GitHub links from prospective employers, and using fake recruitment is a high-level psychological manipulation.

My expert analysis: this campaign demonstrates the growing sophistication of phishing attacks in the crypto industry. Instead of mass mailings, attackers are shifting to targeted, social engineering attacks, leveraging trust in professional platforms. Developers should double-check any links to third-party resources and never run code from untrusted sources, even if the offer looks tempting.