Fake Freelance Job Offers Hide Malware in npm Packages

A Turkish developer discovered a seemingly legitimate NFT staking project pitch that contained a typosquatted npm package designed to steal browser credentials and wallet data—a social engineering attack targeting creators in crypto work-for-hire spaces. The compromise operated at the behavioral level, exploiting freelancers' information-seeking instincts rather than code vulnerabilities alone, making vetting harder for solo workers without institutional security teams. The attack exploited a specific economic desperation: developers and creators pursuing quick crypto gigs are least likely to scrutinize package dependencies or job legitimacy before installing tools.