Security experts from SlowMist have detected a sophisticated phishing campaign targeting Web3 developers. Scammers pose as recruiters on the LinkedIn platform and offer candidates to review fake projects hosted in GitHub repositories.

Inside these repositories, a malicious Node.js loader was hidden, skillfully disguised as a legitimate plugin for Tailwind CSS. Once activated, this code gained full control over the victim's system: stealing personal data, files, cryptocurrency wallet information, executing remote commands, and monitoring the clipboard.

What makes this particularly dangerous is that the attack targets a technically savvy audience—developers who are accustomed to trusting GitHub links and often test third-party projects. Attackers exploit this professional context to bypass standard security precautions.

The attack methodology resembles classic social engineering tactics, adapted to the modern realities of the crypto industry. Developers working with Web3 and DeFi should exercise extreme caution when interacting with unfamiliar repositories, even if they are received through supposedly official hiring channels.

Expert comment: This campaign is a clear example of how scammers adapt to the professional environment. Instead of mass mailings, they conduct targeted attacks on individuals who have access to key projects and wallets. I recommend all developers enable two-factor authentication on GitHub, use isolated environments for testing third-party code, and verify recruiters' reputations through independent sources.