Crypto news

19.07.2026
15:11

Fake job postings on LinkedIn: a new threat for Web3 developers from SlowMist

hack

My colleagues from the analytics team have identified a large-scale malicious operation targeting developers in the Web3 space. Attackers are using LinkedIn to create fake recruiter profiles that offer candidates high-paying job opportunities. During correspondence, victims are sent links to GitHub repositories supposedly containing test projects to assess their skills.

A careful examination of these repositories revealed a Node.js loader hidden within the files. It is cleverly disguised as a legitimate Tailwind plugin—a popular tool among frontend developers. Once executed, the malware begins active operations: stealing personal data, files from the workstation, and information about cryptocurrency wallets. Additionally, it can execute remote commands and monitor clipboard contents, which is particularly dangerous for those who use it to copy wallet addresses or private keys.

This attack demonstrates the growing sophistication of social engineering in the crypto industry. Attackers carefully study developers' professional networks and exploit trust in platforms like GitHub to bypass traditional security measures. I strongly recommend that all Web3 professionals verify the authenticity of recruiters through official channels and avoid running code from untrusted repositories, even if they appear professional.