MistEye found attackers posing as recruiters, building trust through interview chats before sending a malicious GitHub repository disguised as an “interview MVP.”
SlowMist said its MistEye monitoring system recently detected a malicious campaign aimed at developers through fake Web3 job outreach. The attackers allegedly impersonate recruiters on LinkedIn, use conversations about work history and interview experience to build trust, and then send a GitHub code repository presented as an “interview MVP.” Analysis cited by PANews found the repository hid malicious code in theme/js/auron-core.min.js while disguising it as a Tailwind plugin, a tactic that could trick developers into running compromised project files. Once executed, the hidden Node.js loader can deploy payloads to steal browser credentials and wallet data, collect sensitive files, execute remote commands, and monitor clipboard activity. SlowMist advised developers to closely inspect project scripts, dependencies and build configurations before running unknown code.