Fake LinkedIn Web3 Job Offer Hid Malware Designed to Rob Developers
A developer received a LinkedIn message from an unknown recruiter offering a Web3 job and sharing a private GitHub repository to review. The repository appeared to be a functional crypto staking app but contained a hidden malicious file disguised as a styling plugin. Once the project was run or built locally, the file executed silently, stealing browser passwords, crypto wallet data, private keys, and SSH credentials while opening a remote backdoor to the attacker. The developer narrowly avoided the trap by noticing that their AI coding agent — which can execute code, not just read it — could have triggered the payload automatically. The incident highlights a growing threat targeting developers via seemingly routine code-review requests, where the attack activates only when the project is run, not during installation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in