扫码下载
BTC $78,273.75 +2.36%
ETH $2,397.54 +3.30%
BNB $642.63 +1.36%
XRP $1.45 +0.98%
SOL $88.29 +2.81%
TRX $0.3346 +1.66%
DOGE $0.0979 +2.50%
ADA $0.2555 +2.11%
BCH $466.81 +4.84%
LINK $9.52 +1.20%
HYPE $40.93 +0.18%
AAVE $93.46 +0.64%
SUI $0.9701 +1.44%
XLM $0.1795 -0.70%
ZEC $320.36 -3.33%
BTC $78,273.75 +2.36%
ETH $2,397.54 +3.30%
BNB $642.63 +1.36%
XRP $1.45 +0.98%
SOL $88.29 +2.81%
TRX $0.3346 +1.66%
DOGE $0.0979 +2.50%
ADA $0.2555 +2.11%
BCH $466.81 +4.84%
LINK $9.52 +1.20%
HYPE $40.93 +0.18%
AAVE $93.46 +0.64%
SUI $0.9701 +1.44%
XLM $0.1795 -0.70%
ZEC $320.36 -3.33%

V2EX 用户举报招聘套路藏恶意代码,疑似窃取本地私钥

2025-07-28 08:15:26
收藏

ChainCatcher 消息, V2EX 用户 evada 披露在求职过程中遭遇潜在安全风险。其在完成一项基于 GitHub 项目模板的开发任务时,发现项目中的一个 .png 文件实则隐藏了可执行代码,并被 config - overrides. js 调用执行。

evada 怀疑该代码意图窃取本地私钥并进行盗币操作,evada指出,该恶意代码会向特定网址发送请求,下载木马文件并设置为开机自启动,具有极高的隐蔽性和危害性。相关原始仓库现已被举报并删除, V2EX 管理员 Livid 表示已对涉事账号进行彻底封禁。

app_icon
ChainCatcher 与创新者共建Web3世界