SlowMist's analytical department has identified a sophisticated malicious campaign targeting Web3 developers. Attackers use social engineering, posing as recruiters on the LinkedIn platform, to lure victims into a trap.

The attack scheme is as follows: fake "employers" contact potential targets and offer participation in supposedly promising projects. To review the code, they send links to GitHub repositories. These repositories host fake projects whose files contain hidden malicious code.

The key element of the attack is a Node.js loader cleverly disguised as a legitimate Tailwind CSS plugin. The victim, by downloading and running the project, unknowingly activates the malicious payload. After infection, the program gains a wide range of capabilities: theft of personal data, files, and, critically, cryptocurrency wallet data. Additionally, attackers can execute remote commands on the infected device and monitor clipboard contents, which is especially dangerous when copying wallet addresses or private keys.

This campaign is a clear example of the evolution of threats in the crypto industry. Attackers no longer rely solely on technical vulnerabilities; they actively exploit the trust and professional connections of developers. My expert analysis: this attack vector represents a serious threat, as it targets the most knowledgeable and security-conscious audience — developers. I recommend all members of the Web3 community exercise extreme caution when clicking links from unknown "recruiters" and always verify the authenticity of job offers through official company channels. Never run code from untrusted repositories, even if it looks like part of a standard toolkit such as Tailwind.