Dev Radar
Support
LiveUpdated 2026-09-22 08:21 UTC

Attackers posing as a Web3 company used a remote job interview as a pretext to ask a…

🚨SlowMist TI Alert🚨 Attackers posing as a Web3 company used a remote job interview as a pretext to ask a candidate…

This is a dev post classified by Jev as Security (news), kept by the Dev Radar because it carries real work, not commentary.

🚨SlowMist TI Alert🚨 Attackers posing as a Web3 company used a remote job interview as a pretext to ask a candidate to deploy and run a project locally: hxxps://bitbucket[.]org/poc_review58/demoroyalcity Disguised as a real estate and crypto investment application, RoyalCity contained obfuscated malicious code in tailwind.config.js. Running or building the project can trigger payloads capable of stealing browser credentials and wallet extension data, exfiltrating local files, monitoring clipboard contents, and enabling remote control. A separate server-side backdoor in errorHandler.js retri

Posted by SlowMist (89.8k followers) 1 h ago · 8 likes · 1.5k views · view the original post on X. Kept by the Dev Radar as Security. Tools mentioned: MistEye.

More dev work like this

Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 20.7k posts from 4.9k X accounts over the last 21 days, 2.4k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-22 08:21 UTC. Full method.