A cyber campaign targeted blockchain developers through a fake recruitment process that directed victims to a polished GitHub repository posing as a legitimate company project. Investigators found multiple hidden compromise paths in the codebase, including a malicious VSCode task that could run when the folder was opened and a trojanized npm dependency that delivered another infection route. The operation used a multi-stage chain with short-lived JWTs, behavior-based filtering on command-and-control infrastructure, and anti-analysis measures designed to frustrate defenders.
Analysis of the repository’s 574 commits uncovered four malicious artifacts and showed how the attackers blended social engineering with developer tooling abuse to gain execution on targets’ machines. Researchers reported that AI-assisted review significantly accelerated static analysis and helped reconstruct the attack chain, while human validation remained necessary to correct false assumptions during investigation, including the discovery that failed second-stage requests were tied to User-Agent filtering that expected an npm-like fingerprint rather than simple IP-based blocking.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Quarkslab published a blog post titled "From prompt to pwned: chaining LLM and web bugs to Admin." No further event details are available in the provided content beyond the publication itself.
Intrinsec published an analysis of a cyber campaign that used a fraudulent company, a fake recruitment process, and a prepared GitHub repository to target blockchain developers. The report describes hidden compromise mechanisms including a malicious VSCode task and a trojanized npm dependency, along with a multi-stage staging chain and analysis-resistant infrastructure.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.