SlowMist has uncovered a large-scale attack on Web3 developers through fake job postings on GitHub.
SlowMist analysts have uncovered a new malicious campaign targeting Web3 developers. Attackers are using fake job offers to inject malware into the blockchain project ecosystem.
The attack scheme is as follows: hackers create fake recruiter profiles on LinkedIn and send developers links to GitHub repositories. These repositories contain supposedly legitimate projects, but in reality, a hidden Node.js loader disguised as a Tailwind CSS plugin is embedded in the files.
What does the malware do? Once activated, it gains access to critical data: personal information, files, and cryptocurrency wallet data. Additionally, the malware can execute remote commands and monitor clipboard contents, allowing it to intercept passwords and seed phrases.
Why is this important for the community?
Web3 developers are one of the most valuable targets for attacks, as they have direct access to smart contracts, private keys, and DeFi project infrastructure. This campaign demonstrates that attackers are increasingly using social engineering combined with technical vulnerabilities.
My expert assessment: This is not an isolated incident — such attacks will multiply. I recommend that all developers verify the authenticity of recruiters through independent channels and only run code from GitHub repositories in an isolated environment. Security in Web3 begins with cyber hygiene at the hiring stage.