SlowMist Security Team recently issued a warning: a malicious activity targeting developers has not just appeared recently, but has been present on GitHub for the past 7 months.



Specifically, attackers use fake job postings as bait to lure developers into downloading what appears to be a normal VS Code project. When you open this project, hidden malicious tasks will quietly run—users are often unaware. Once activated, these tasks can steal sensitive data from services like Vercel.

This method is particularly dangerous because it targets the developer community. Job hunting season makes it especially easy to fall for such scams. The security team emphasizes that developers must stay vigilant when encountering unfamiliar code projects, especially when the recruitment channels are unverified. Additionally, regularly reviewing VS Code extensions and project configurations for abnormal startup scripts or background tasks is an important step in prevention.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 6
  • Repost
  • Share
Comment
0/400
DuckFluffvip
· 14h ago
Damn, the phishing job postings on GitHub have been hidden for 7 months? How many people have fallen for it? Just realized this trick is really clever, as soon as you open the project, data starts being stolen Job seekers, be more cautious. For offers from unknown sources, ask three times first VS Code needs to be checked regularly, or you won't know what’s happening behind the scenes Recruitment season requires extra caution, there are a bunch of scammers This move is well done, a warning to all developers
View OriginalReply0
DegenMcsleeplessvip
· 14h ago
Damn, it was already there 7 months ago? Why is the warning only coming out now? The developers must have already been affected, right?
View OriginalReply0
StealthMoonvip
· 14h ago
Damn, how ruthless is this trick? No one noticed for 7 months?
View OriginalReply0
SellTheBouncevip
· 14h ago
Started 7 months ago? That shows we've been taking the fall all along. Developers are the easiest to be fooled—human weakness. When you're eager to find a job, you'll believe anything.
View OriginalReply0
OnChain_Detectivevip
· 14h ago
yo seven months?? pattern analysis screaming this is way deeper than some random github incident... suspicious activity detected across multiple vectors here
Reply0
MetaverseVagrantvip
· 14h ago
Wow, fake job postings to trick developers into downloading malicious projects? This trick is so old... But someone actually fell for it? It's been 7 months, and no one has noticed?
View OriginalReply0
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)