My colleagues at SlowMist have detected a new targeted attack on Web3 developers. The attackers orchestrated a multi-stage social engineering scheme, using LinkedIn as the entry point. They posed as recruiters and invited applicants to review projects on GitHub.
The malicious code was hidden inside files that appeared to be legitimate Tailwind plugins. In reality, it was a Node.js loader that executed a full range of spy functions: from stealing personal data and files to intercepting clipboard contents and executing remote commands. Particularly dangerous was the fact that the malware targeted cryptocurrency wallet data.
This is yet another reminder that the Web3 sector remains a prime target for sophisticated social attacks. Developers are a key asset of the industry, and attackers know well that through them, they can gain access to confidential projects and funds. I recommend always verifying the authenticity of recruiters through alternative communication channels and never running code from untrusted repositories, even if the offer looks very tempting.
My expert opinion: This attack demonstrates the evolution of threats—from simple phishing to a full-fledged multi-stage operation where every step is carefully planned. The industry needs to implement mandatory verification protocols for all external communications, especially during hiring. Ignoring these risks could cost developers not only their jobs but also all their funds.