Flash News

SlowMist: Analyzing the malicious code of recruitment in GitHub

The SlowMist security team analysed a drug attack disguised as a recruitment attack by GitHub, who contacted the developer through LinkedIn, pretending to be a recruiter for the Web3 project, to induce the target to download the malicious code. The attack process mimics a real technical interview, and the developer applies the malicious code without knowledge. SlowMist found that the malicious code was loaded through a document called theme/js/auron-core.min.js, which was not a legitimate front-end component, but a first stage loader of the malicious software, which was responsible for initiating several hidden Node.js subprocesses and injecting them into a second stage script, stealing browser and wallet data. The risk of the attack was that the malicious code would be implemented only when the target was cloned and the project was initiated。

OKX - Unlock Rewards