Analysts at SlowMist, a leading blockchain security firm, have identified a new sophisticated campaign targeting Web3 developers. Attackers are using fake job offers to inject malware into their systems.
Attack Scheme: Social Engineering via LinkedIn
The primary attack vector is social engineering through the professional network LinkedIn. Hackers disguise themselves as recruiters and send developers links to GitHub repositories supposedly containing test projects or technical assignments for skill assessment.
Inside these repositories, a hidden Node.js loader is cleverly disguised by the attackers as a legitimate Tailwind CSS plugin. This file is executed when a developer attempts to install or test the "project."
Malware Functionality: Full System Control
Once activated, the malware performs a range of data theft tasks. It extracts personal information, files from the workstation, and cryptocurrency wallet data. Additionally, the loader can execute remote commands, giving hackers full control over the infected device, and monitor clipboard contents to intercept copied wallet addresses or seed phrases.
This attack demonstrates that threats in the crypto industry are becoming increasingly targeted and professional. Attackers exploit trust in platforms like LinkedIn and GitHub, making this scheme particularly dangerous.
Expert Opinion: This campaign is a stark example of the evolution of phishing in Web3. Developers must exercise maximum vigilance: verify recruiter identities, avoid running untrusted code from repositories, and always use hardware wallets for storing assets to minimize risks even if a workstation is compromised.