๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
๊ฐ€์ž… April 2018
410 ํŒ”๋กœ์ž‰ ์ค‘    90.5K ํŒฌ
๐ŸšจSlowMist TI Alert๐Ÿšจ Attackers posing as a Web3 company used a remote job interview as a pretext to ask a candidate to deploy and run a project locally: hxxps://bitbucket[.]org/poc_review58/demoroyalcity Disguised as a real estate and crypto investment application, RoyalCity contained obfuscated malicious code in tailwind.config.js. Running or building the project can trigger payloads capable of stealing browser credentials and wallet extension data, exfiltrating local files, monitoring clipboard contents, and enabling remote control. A separate server-side backdoor in errorHandler.js retrieves and executes remote code. This case closely resembles the recruitment-themed GitHub poisoning attack we previously analyzed, sharing the interview lure, execution through Tailwind, and highly similar payloads for data theft and remote access. Our previous analysis ( provides more detail on this attack pattern. ๐Ÿ” IOCs Malicious IP: 144[.]172[.]107[.]50 Malicious domain: server-azure-tau[.]vercel[.]app URLs: hxxp://144[.]172[.]107[.]50:8085/upload hxxp://144[.]172[.]107[.]50:8086/upload ws://144[.]172[.]107[.]50:8087 hxxps://server-azure-tau[.]vercel[.]app/api/ipcheck-encrypted/604 Malicious dependency/repository reference: bitbucket:https://bitbucket[.]org/poc_review58/demoroyalcity Malicious files โ€” SHA-256: tailwind.config.js 62a98662f2f84001edd71b68e8fa318140c750ba9af096f5e4c9a0bb5502eb6e errorHandler.js d6705f52757af8bc2708a39647fc8c34dc02ffab7838a1d9c10fd44cfe9a7081 โš ๏ธ Verify recruiters independently. Review unfamiliar projects before running them, and keep interview tasks isolated from your everyday development environment, wallets, and sensitive credentials. You can also visit to check for free whether the npm packages, pip packages, domains, or IPs you use are safe. As always, stay vigilant! Thanks to @jhh_kh37332 for sharing the lead.
๋” ๋ณด๊ธฐ