02:13
SlowMist Cosine: Job seeker falls victim to "backdoor data theft" while reviewing code, private key directly stolen
ChainCatcher reports that SlowMist’s Yu Xian (@evilcos) has issued a warning about Web3 job seekers encountering malicious code traps during interviews. In this incident, an attacker impersonated @seracleofficial and asked the candidate to review and run code from Bitbucket. After the victim cloned the code, the program immediately scanned all local .env files and stole sensitive information such as private keys. SlowMist pointed out that this type of backdoor is a typical stealer, capable of collecting browser-saved passwords, crypto wallet mnemonics, private keys, and other private data. Experts emphasize that any review of suspicious code must be conducted in an isolated environment and not run directly on a real device to avoid attacks.

