The SlowMist security team has issued a warning about phishing attacks targeting blockchain engineers on the LinkedIn platform. Blockchain developer Bruno Skvorc fell victim to a recruitment phishing attack aimed at blockchain engineers. The attackers posed as project parties, providing a Bitbucket repository link containing malicious code.
Technical analysis by the SlowMist team revealed that hidden within this malicious code was an encrypted payload, activated through the server.js file. Once run, the program connects to a command and control server, downloads test.js and .npl trojan programs, then proceeds to steal system information, browser extension wallet data and passwords among other sensitive information. The ultimate goal is to steal users' encrypted assets.