SlowMist has issued a security alert stating that North Korea’s Lazarus group, through its HexagonalRodent faction, is using social engineering tactics such as “high-paying remote positions” and “recruitment for well-known projects” to trick Web3 developers into executing malicious code and stealing crypto assets. On March 9, 2026, a user with the same name as a fast-draft extension developer was infected with the OtterCookie malware, which was used to distribute additional malicious software. The attackers are also extensively using ChatGPT and Cursor to enhance their deception and impersonation capabilities.
SlowMist Warns of Lazarus Group’s Social Engineering Attacks on Web3 Developers
AiCoinShare
Web3 news broke today as SlowMist reported a new threat from the Lazarus Group’s HexagonalRodent team. Attackers are using social engineering to target Web3 developers with fake job offers and project recruitment. A developer was infected with the OtterCookie malware on March 9, 2026. The distribution of malicious code is increasing, with tools like ChatGPT and Cursor being used to enhance deception. While Web3 adoption continues to grow, so too do these targeted attacks. Developers are urged to verify all communications and avoid executing unverified code.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.



