hexcast.
ANNOUNCEMENT

GitHub Poisoning Campaign Uses Fake Recruiters to Target Developers

MistEye detected a malicious code delivery campaign targeting developers via fake LinkedIn recruiters. Attackers sent a GitHub repository disguised as an MVP for pre-interview review. Malware loaded through Tailwind plugin theme/js/auron-core.min.js when developers ran the project. It spawned hidden Node.js processes, stealing browser and wallet data, uploading local files, and establishing remote control.

SLOWMIST.MEDIUM.COM · JUL 18