According to SlowMist’s disclosure, there was a recruiting poisoning attack targeting Web3 job seekers. The attacker impersonated a Web3 company and, under the pretext of a remote interview, asked candidates to set up and run a project called “RoyalCity” locally. After running or building the project, the attacker could steal browser credentials, wallet extension data, and local files, monitor the clipboard, and enable remote control. SlowMist said the project also implanted a server backdoor in its errorHandler.js, allowing the download and execution of remote code. Its attack methods are highly similar to a prior GitHub recruiting poisoning incident.
