BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

SlowMist Cosine: Job seeker falls victim to "backdoor theft" while reviewing code; private key directly stolen.

2025-12-04 02:11

Odaily Planet Daily reports that SlowMist's @evilcos has warned of a malicious code trap encountered by Web3 job seekers during interviews. In this incident, the attacker impersonated @seracleofficial, requesting the job seeker to review and run code on Bitbucket. After cloning the code, the program immediately scanned all local .env files and stole sensitive information such as private keys.

SlowMist points out that this type of backdoor is a typical stealer, capable of collecting private data such as passwords, encrypted wallet mnemonic phrases, and private keys saved by browsers. Experts emphasize that any review of suspicious code must be conducted in an isolated environment to avoid running it directly on real devices and thus becoming vulnerable to attack.