Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Web3 Developers Targeted by Fake Recruiters

Web3 Developers Targeted by Fake Recruiters

Posted on July 29, 2026 By CWS

Web3 developers are increasingly becoming targets of sophisticated job scams orchestrated by fake recruiters. These fraudulent schemes involve imposters posing as legitimate recruiters, engaging with developers and directing them to use a counterfeit meeting tool that mimics standard remote hiring practices.

Deceptive Recruitment Tactics

The scam unfolds with attackers approaching developers about potential interviews, eventually guiding them to download a supposed AI meeting application called ‘Relay.’ This app falsely claims to offer features like meeting notes and transcripts. However, cybersecurity experts from SlowMist have identified this as a facade for an info-stealing campaign aimed at extracting sensitive data from crypto and blockchain professionals.

Upon execution, the fake software attempts to capture browser passwords, wallet extensions, Telegram sessions, and other valuable system information, leading to potential significant financial losses for the victims. Such breaches can compromise personal wallets, work accounts, and other confidential digital assets.

Execution and Impact

The modus operandi of these scams involves directing victims to the website relay.lc, which masquerades as a legitimate collaboration platform. Victims are instructed to install a meeting client, a seemingly innocuous step that rarely raises suspicions. On macOS systems, users are misled into running Terminal commands that discreetly install malicious programs, while Windows users encounter deceptive installation progress bars that disguise harmful processes.

This tactic is part of a broader trend where malicious actors exploit trusted developer channels, such as npm packages or coding tests, to deliver harmful code under the guise of legitimate tools. The aim is to exploit the inherent trust developers place in common work-related software.

Preventive Measures and Recommendations

To mitigate the risk of falling victim to such scams, it is crucial for developers and organizations to treat unsolicited software installation requests with skepticism, especially when associated with recruitment processes. If the macOS variant of the application is executed, users should disconnect from the network, change their passwords from a clean device, and secure their digital assets with new keys. Windows users should similarly isolate infected systems, remove malicious files, and consider a complete OS reinstallation if contamination is confirmed.

Cybersecurity teams are advised to monitor for indicators of compromise, such as specific domains and file hashes associated with these scams, and to maintain vigilance against similar deceptive practices targeting developers.

Conclusion

The ongoing threat to Web3 developers underscores the need for increased awareness and robust cybersecurity measures. By understanding the tactics employed by these malicious actors, developers can better protect themselves and their digital assets from potential exploitation.

Cyber Security News Tags:Bitbucket, Blockchain, Crypto, cyber security, cyber threat, developer scam, fake recruiters, info-stealing, job scams, macOS, Malware, NPM, remote hiring, Web3, Windows

Post navigation

Previous Post: VMware ESXi Security Flaws Patched by Broadcom
Next Post: Critical Flaw in Ruflo Allows Remote Code Execution

Related Posts

SentinelOne Global Service Outage Root Cause Revealed SentinelOne Global Service Outage Root Cause Revealed Cyber Security News
US Military’s Controversial Use of Claude AI in Iran Strike US Military’s Controversial Use of Claude AI in Iran Strike Cyber Security News
APT Hackers Attacking Maritime and Shipping Industry to Launch Ransomware Attacks APT Hackers Attacking Maritime and Shipping Industry to Launch Ransomware Attacks Cyber Security News
Authorities Dismantled AVCheck, a Tool For Testing Malware Against Antivirus Detection Authorities Dismantled AVCheck, a Tool For Testing Malware Against Antivirus Detection Cyber Security News
The Necessity of 24/7 Support in Cybersecurity The Necessity of 24/7 Support in Cybersecurity Cyber Security News
Darknet Market Archetyp Dismantled by Authorities in Joint Action ‘Operation Deep Sentinel’ Darknet Market Archetyp Dismantled by Authorities in Joint Action ‘Operation Deep Sentinel’ Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerability in NVIDIA BlueField DPUs Exposes Systems
  • OpenAI Models Exploit JFrog Zero-Day in Major Hack
  • Critical Flaw in Ruflo Allows Remote Code Execution
  • Web3 Developers Targeted by Fake Recruiters
  • VMware ESXi Security Flaws Patched by Broadcom

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerability in NVIDIA BlueField DPUs Exposes Systems
  • OpenAI Models Exploit JFrog Zero-Day in Major Hack
  • Critical Flaw in Ruflo Allows Remote Code Execution
  • Web3 Developers Targeted by Fake Recruiters
  • VMware ESXi Security Flaws Patched by Broadcom

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark