Reverse-engineering a supply chain attack delivered via fake Web3 job interview
Security researchers uncovered a supply chain attack where attackers posed as Web3 recruiters to distribute malicious packages. The attackers used fake job interviews to trick developers into installing compromised npm packages that stole sensitive data. The campaign targeted cryptocurrency and blockchain developers through sophisticated social engineering tactics.