Fake Recruiters Exploit Bitbucket, npm to Target Web3 Developers
Key Takeaways A sophisticated phishing campaign is targeting Web3 developers through fake job offers. Attackers impersonate recruiters and trick victims into downloading malicious...
Key Takeaways
- A sophisticated phishing campaign is targeting Web3 developers through fake job offers.
- Attackers impersonate recruiters and trick victims into downloading malicious “interview” software named “Relay.”
- The malware, designed for both Windows and macOS, steals sensitive data, including browser passwords, crypto wallet extensions, Telegram sessions, and system information.
- The campaign leverages social engineering to exploit trust in hiring processes, leading users to self-infect their devices.
- No specific software vulnerabilities are exploited; the attack relies entirely on user interaction.
Sophisticated Job Scams Target Web3 Developers with Malicious “Interview” Software
A new and insidious wave of job scams is actively preying on Web3 developers, leveraging the common desire for career advancement to deliver information-stealing malware. Threat actors are masquerading as legitimate recruiters, initiating seemingly authentic conversations about job interviews, only to direct unsuspecting candidates toward a deceptive meeting application designed to compromise their systems.
Table Of Content
The scam is meticulously crafted, presenting a polished facade. Victims are instructed to install an application called “Relay,” which is advertised as an advanced AI meeting tool featuring note-taking, transcription capabilities, and dedicated desktop clients for both Windows and macOS. This seemingly innocuous request, typical of modern remote hiring processes, serves as the gateway for the attack.
Following this second stage of contact, analysts from SlowMist meticulously investigated the website and its associated installers, identifying them as components of a carefully constructed info-stealing operation specifically engineered to target talent within the cryptocurrency and blockchain sectors. SlowMist said in a report that once the fraudulent application is executed, it begins to extract a wide array of sensitive data. This includes browser passwords, credentials for crypto wallet extensions, active Telegram sessions, personal notes, and detailed system information, all of which can facilitate significant financial losses for the victim.
The ramifications of a successful compromise extend far beyond a single stolen login. A single infected device can expose personal cryptocurrency wallets, corporate accounts, and any confidential information a developer might store within their daily tools. This campaign mirrors other recent incidents where similar deceptive job interview tactics have swiftly escalated from a simple trust exploit to a complete device compromise.
Attack Vector and Execution
The attack sequence begins with initial messages pertaining to interview schedules, after which candidates are directed to the malicious website, relay.lc. This site is designed to appear as a contemporary collaboration platform, making the request to install a meeting client before a subsequent interview round seem entirely normal and thus, less likely to trigger suspicion.
For macOS users, victims are instructed to open Terminal, drag a specific file into the window, and then press Enter. This seemingly benign action surreptitiously copies a hidden program, bypasses macOS’s built-in security warnings, and launches the malicious payload in the background. The disk image itself does not contain a legitimate application bundle, but rather a concealed executable designed for covert operations.
On Windows systems, the installer displays a progress bar indicating “Updating,” which is a deceptive visual unrelated to any actual software update. As this bar approaches approximately 80%, the malicious code attempts to launch an unsigned helper application with elevated administrative privileges and a hidden window. Both the macOS and Windows execution paths are meticulously crafted to exploit user habits and expectations associated with standard remote hiring procedures.
This attack methodology aligns with other campaigns that have utilized malicious npm packages or fraudulent coding tests distributed through trusted developer channels. The underlying principle remains consistent: exploit the inherent trust users place in everyday work tools to deliver and execute malicious code under the guise of legitimate activity.
Dual-Platform Data Theft Capabilities
The macOS payload is designed to present a fake “Application Error” dialog box, prompting the user for their system password. Concurrently, it extracts data from the login Keychain file, preparing both the entered password and the Keychain contents for exfiltration. Furthermore, it aggressively targets browser data stores, cryptocurrency wallet extensions, Telegram session data, and even Apple Notes, where users sometimes inadvertently store sensitive information like crypto seed phrases.
The Windows variant prioritizes persistence, establishing copies of itself and creating startup entries under names that mimic legitimate system updates. It then proceeds to scan the process memory of Chrome and Brave extensions for wallet unlock material, dispatching the findings to external command-and-control servers. Browser cookies, authentication tokens, and clues related to desktop wallet applications are also within its scope. Crucially, neither attack chain relies on exploiting novel software vulnerabilities; instead, users are manipulated into voluntarily executing the malicious code. Previous macOS job scams have employed similar social engineering tactics, leveraging the pressure of interviews to deploy remote access tools and information stealers.
What You Should Do
- If a file was only downloaded: Immediately delete the malicious file and empty your Trash or Recycle Bin. Block all identified domains and hashes associated with the Indicators of Compromise (IoCs) in your firewall or security solutions.
- If the macOS sample ran: Disconnect your device from the network immediately without rebooting. From a clean, uncompromised device, change your login and Apple ID passwords. Revoke all active browser and Telegram sessions. Transfer all cryptocurrency assets from compromised wallets to new wallets with freshly generated keys. Consider a full operating system reinstallation.
- If the Windows sample ran: Isolate the infected host from the network. After preserving any necessary forensic evidence, remove the planted update-style files and startup entries. From a clean machine, rotate all compromised credentials. A full operating system reinstallation is strongly recommended to ensure complete eradication of the malware.
- For all users: Exercise extreme caution with unsolicited installation requests, especially those related to job interviews or coding tests. Treat any request to install software from an unknown source as hostile until its legitimacy can be independently verified.
- For organizations: Implement robust endpoint detection and response (EDR) solutions. Educate employees, particularly developers, about sophisticated phishing and social engineering tactics. Continuously monitor network traffic for connections to known malicious domains and IP addresses.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.