216.73.217.22

Uncovering a Web3 Interview Scam

· Published 13/08/2025 11:57 · Modified 13/08/2025 15:47

Export JSON

Essential information

Published
13/08/2025 11:57
Modified
13/08/2025 15:47
Tags
2025-08-13 cryptocurrency data theft github interview scam malware npm package redux-ace rtk-logger web3
Related entities
12 techniques (mitre), 2 malware, 1 others

Description

A Ukrainian team's interview process involved cloning a repository containing malicious components. Analysis revealed the project replaced a legitimate dependency with a malicious , @1.11.5. This package collected sensitive data, including wallet information, from popular browsers and uploaded it to an attacker-controlled server. The also implemented keylogging, screen capture, and clipboard monitoring. Two other accounts were found using a similar malicious package. The scam aimed to trick interviewees into executing malicious code, potentially leading to data leaks and asset theft. Developers are advised to exercise caution when handling unknown projects and to use isolated environments for execution.

External references