SlowMist flags job-interview phishing campaign disguised as a Web3 hiring process

SlowMist flags job-interview phishing campaign disguised as a Web3 hiring process

N
News Editor
2026-09-22 07:31:33
SlowMist said attackers are posing as Web3 companies and using remote job interviews as bait to get candidates to deploy and run a local project. The project is presented as RoyalCity, a real estate and crypto investment app, but its tailwind.config.js file contains obfuscated malicious code. Once the project is run or built, the payload can steal browser credentials, wallet extension data, exfiltrate local files, monitor clipboard content, and enable remote control of the victim’s machine. SlowMist also said errorHandler.js contains a separate server-side backdoor that can retrieve and execute remote code. According to the security team, the case closely resembles a previously analyzed recruitment-themed GitHub poisoning attack: both used interview lures, executed through Tailwind, and carried highly similar data theft and remote access payloads. The disclosure was published by @SlowMist_Team and carried by Techub News.

Techub News reported that SlowMist said on X that attackers are impersonating Web3 companies and using remote interviews as a lure, asking candidates to deploy and run a project locally.

The project is disguised as RoyalCity, described as a real estate and cryptocurrency investment app. SlowMist said the project’s tailwind.config.js file contains obfuscated malicious code. Running or building the project triggers a payload that can steal browser credentials, wallet extension data, exfiltrate local files, monitor clipboard content, and enable remote control.

SlowMist added that errorHandler.js contains a separate server-side backdoor capable of retrieving and executing remote code.

According to the team, the case closely resembles a previously analyzed recruitment-themed GitHub poisoning attack. In both cases, the attackers used interview bait, executed through Tailwind, and deployed highly similar data-stealing and remote-access payloads.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.