Analysts have identified a new sophisticated campaign targeting Web3 developers. Attackers pose as recruiters on LinkedIn and offer job seekers positions, subsequently sending links to GitHub repositories containing fake projects.

Attack Scheme

Inside the repositories, supposedly dedicated to legitimate tasks, a Node.js loader is hidden. It is carefully disguised as a Tailwind plugin, making it virtually undetectable by standard verification tools. Once launched, the malware gains control over the victim's system.

What is Stolen?

The attack targets include theft of personal data, files, and information about cryptocurrency wallets. Moreover, the malware is capable of executing remote commands and monitoring the clipboard. This allows intercepting addresses for fund transfers and replacing them with the attackers' addresses — a classic technique for stealing cryptocurrency.

Threat Scalability

Social engineering methods via LinkedIn are becoming increasingly popular among cybercriminals. Using fake job postings allows attacks not only on developers but also on other specialists working in a decentralized environment. The particular danger lies in the fact that victims themselves launch the malware, trusting a link from a "recruiter."

Expert Comment: This campaign demonstrates how attackers are adapting to the Web3 job market. It is critically important for developers to verify any links and repositories received from unfamiliar "employers," even if they appear professional. Installing antivirus software and using isolated environments for testing third-party projects are not luxuries but necessities in the current conditions.