Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical VMware Flaws Let Attackers Bypass Authentication, Access Systems
July 29, 2026
Houston City College Data Breach Exposes 832,000 Student Emails
July 29, 2026
AsyncAPI Malware Steals GitHub, npm, Cloud, and AI API Credentials
July 29, 2026
Home/Threats/Fake Recruiters Exploit Bitbucket, npm to Target Web3 Developers
Threats

Fake Recruiters Exploit Bitbucket, npm to Target Web3 Developers

Key Takeaways A sophisticated phishing campaign is targeting Web3 developers through fake job offers. Attackers impersonate recruiters and trick victims into downloading malicious...

Jennifer sherman
Jennifer sherman
July 29, 2026 4 Min Read
2 0

Key Takeaways

  • A sophisticated phishing campaign is targeting Web3 developers through fake job offers.
  • Attackers impersonate recruiters and trick victims into downloading malicious “interview” software named “Relay.”
  • The malware, designed for both Windows and macOS, steals sensitive data, including browser passwords, crypto wallet extensions, Telegram sessions, and system information.
  • The campaign leverages social engineering to exploit trust in hiring processes, leading users to self-infect their devices.
  • No specific software vulnerabilities are exploited; the attack relies entirely on user interaction.

Sophisticated Job Scams Target Web3 Developers with Malicious “Interview” Software

A new and insidious wave of job scams is actively preying on Web3 developers, leveraging the common desire for career advancement to deliver information-stealing malware. Threat actors are masquerading as legitimate recruiters, initiating seemingly authentic conversations about job interviews, only to direct unsuspecting candidates toward a deceptive meeting application designed to compromise their systems.

Table Of Content

  • Key Takeaways
  • Sophisticated Job Scams Target Web3 Developers with Malicious “Interview” Software
  • Attack Vector and Execution
  • Dual-Platform Data Theft Capabilities
  • What You Should Do

The scam is meticulously crafted, presenting a polished facade. Victims are instructed to install an application called “Relay,” which is advertised as an advanced AI meeting tool featuring note-taking, transcription capabilities, and dedicated desktop clients for both Windows and macOS. This seemingly innocuous request, typical of modern remote hiring processes, serves as the gateway for the attack.

Following this second stage of contact, analysts from SlowMist meticulously investigated the website and its associated installers, identifying them as components of a carefully constructed info-stealing operation specifically engineered to target talent within the cryptocurrency and blockchain sectors. SlowMist said in a report that once the fraudulent application is executed, it begins to extract a wide array of sensitive data. This includes browser passwords, credentials for crypto wallet extensions, active Telegram sessions, personal notes, and detailed system information, all of which can facilitate significant financial losses for the victim.

The ramifications of a successful compromise extend far beyond a single stolen login. A single infected device can expose personal cryptocurrency wallets, corporate accounts, and any confidential information a developer might store within their daily tools. This campaign mirrors other recent incidents where similar deceptive job interview tactics have swiftly escalated from a simple trust exploit to a complete device compromise.

Attack Vector and Execution

The attack sequence begins with initial messages pertaining to interview schedules, after which candidates are directed to the malicious website, relay.lc. This site is designed to appear as a contemporary collaboration platform, making the request to install a meeting client before a subsequent interview round seem entirely normal and thus, less likely to trigger suspicion.

For macOS users, victims are instructed to open Terminal, drag a specific file into the window, and then press Enter. This seemingly benign action surreptitiously copies a hidden program, bypasses macOS’s built-in security warnings, and launches the malicious payload in the background. The disk image itself does not contain a legitimate application bundle, but rather a concealed executable designed for covert operations.

On Windows systems, the installer displays a progress bar indicating “Updating,” which is a deceptive visual unrelated to any actual software update. As this bar approaches approximately 80%, the malicious code attempts to launch an unsigned helper application with elevated administrative privileges and a hidden window. Both the macOS and Windows execution paths are meticulously crafted to exploit user habits and expectations associated with standard remote hiring procedures.

This attack methodology aligns with other campaigns that have utilized malicious npm packages or fraudulent coding tests distributed through trusted developer channels. The underlying principle remains consistent: exploit the inherent trust users place in everyday work tools to deliver and execute malicious code under the guise of legitimate activity.

Dual-Platform Data Theft Capabilities

The macOS payload is designed to present a fake “Application Error” dialog box, prompting the user for their system password. Concurrently, it extracts data from the login Keychain file, preparing both the entered password and the Keychain contents for exfiltration. Furthermore, it aggressively targets browser data stores, cryptocurrency wallet extensions, Telegram session data, and even Apple Notes, where users sometimes inadvertently store sensitive information like crypto seed phrases.

The Windows variant prioritizes persistence, establishing copies of itself and creating startup entries under names that mimic legitimate system updates. It then proceeds to scan the process memory of Chrome and Brave extensions for wallet unlock material, dispatching the findings to external command-and-control servers. Browser cookies, authentication tokens, and clues related to desktop wallet applications are also within its scope. Crucially, neither attack chain relies on exploiting novel software vulnerabilities; instead, users are manipulated into voluntarily executing the malicious code. Previous macOS job scams have employed similar social engineering tactics, leveraging the pressure of interviews to deploy remote access tools and information stealers.

What You Should Do

  • If a file was only downloaded: Immediately delete the malicious file and empty your Trash or Recycle Bin. Block all identified domains and hashes associated with the Indicators of Compromise (IoCs) in your firewall or security solutions.
  • If the macOS sample ran: Disconnect your device from the network immediately without rebooting. From a clean, uncompromised device, change your login and Apple ID passwords. Revoke all active browser and Telegram sessions. Transfer all cryptocurrency assets from compromised wallets to new wallets with freshly generated keys. Consider a full operating system reinstallation.
  • If the Windows sample ran: Isolate the infected host from the network. After preserving any necessary forensic evidence, remove the planted update-style files and startup entries. From a clean machine, rotate all compromised credentials. A full operating system reinstallation is strongly recommended to ensure complete eradication of the malware.
  • For all users: Exercise extreme caution with unsolicited installation requests, especially those related to job interviews or coding tests. Treat any request to install software from an unknown source as hostile until its legitimacy can be independently verified.
  • For organizations: Implement robust endpoint detection and response (EDR) solutions. Educate employees, particularly developers, about sophisticated phishing and social engineering tactics. Continuously monitor network traffic for connections to known malicious domains and IP addresses.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

VulnGym AI-Trained APTs Stress-Test Enterprise Patching Strategies

Next Post

AsyncAPI Malware Steals GitHub, npm, Cloud, and AI API Credentials

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Urges Critical Infrastructure to Isolate Systems From Networks
July 29, 2026
Leaked Android RAT used in attacks by 170 servers, successor emerging
July 29, 2026
20-Year-Old Vulnerability Enables Takeover of Thousands of Data Centers in Minutes
July 29, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us