Attackers posing as a Web3 company used a remote job interview as a pretext to ask a…
This is a dev post classified by Jev as Security (news), kept by the Dev Radar because it carries real work, not commentary.
🚨SlowMist TI Alert🚨 Attackers posing as a Web3 company used a remote job interview as a pretext to ask a candidate to deploy and run a project locally: hxxps://bitbucket[.]org/poc_review58/demoroyalcity Disguised as a real estate and crypto investment application, RoyalCity contained obfuscated malicious code in tailwind.config.js. Running or building the project can trigger payloads capable of stealing browser credentials and wallet extension data, exfiltrating local files, monitoring clipboard contents, and enabling remote control. A separate server-side backdoor in errorHandler.js retri
Posted by SlowMist (89.8k followers) 1 h ago · 8 likes · 1.5k views · view the original post on X. Kept by the Dev Radar as Security. Tools mentioned: MistEye.
More dev work like this
- Yep — @thorstenball
- 🚨SlowMist TI Alert: TraderTraitor Resurfaces via Weaponized Terraform Projects🚨 — @SlowMist_Team
- AI Agent 会写代码、会搜资料,但遇到真实安全事件,很多时候还是不知道该从哪里下手。 — @bkdgiffug
- Here's an API security question I wish every developer would ask: — @shehackspurple
- Theorem co-founder @diagram_chaser reveals the one-line change that took verifying… — @MTSlive
- 80–90% of modern applications rely on open-source code you didn't write - making… — @jfrog
- One of my favorite lessons from #Plugin4Shell has almost nothing to do with AI. — @shehackspurple
- Every #developer now manages a team of agents. — @jfrog
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 20.7k posts from 4.9k X accounts over the last 21 days, 2.4k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-22 08:21 UTC. Full method.