SlowMist: LinkedIn Recruiters Target Web3 Devs With Malware

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- SlowMist reported a malware campaign targeting Web3 developers through fake LinkedIn recruitment messages from attackers posing as Web3 recruiters
- The attackers send victims malicious GitHub repositories disguised as minimum viable product code candidates need to trial before a technical interview
- The infection workflow mimics legitimate developer hiring — pulling code, installing dependencies, and launching a project — making the malicious activity difficult to detect
- The payload is a full remote access trojan designed to steal project keys, cloud credentials, and browser wallet extension data from infected developer machines
- SlowMist said the campaign is not isolated, noting that attackers are increasingly exploiting recruitment, code review, and project collaboration scenarios to get developers to actively run malicious repositories
- One day earlier, SlowMist separately disclosed a macOS malware campaign that stole credentials, hijacked Telegram sessions, and tricked investors into entering wallet recovery phrases on fake websites
Why it matters: Web3 developers routinely custody keys to project treasuries and protocol infrastructure, so a single successful RAT infection can simultaneously drain individual wallets and compromise entire dapps. By weaponizing the trust norms of recruitment and open-source collaboration, attackers turn the developer workflow itself into the delivery mechanism — meaning the threat targets people whose day job requires running unvetted code.




