A recent security alert from SlowMist warns of the North Korean Lazarus Group's HexagonalRodent team targeting Web3 developers. According to PANews, the attackers employ social engineering tactics such as offering 'high-paying remote positions' and 'recruitment for well-known projects' to lure victims into executing malicious code, ultimately stealing crypto assets. On March 9, 2026, a user with the same name as a fast-draft extension developer was infected with the OtterCookie malware, which was used to distribute malicious programs. The attackers extensively use ChatGPT and Cursor to enhance their disguise and deception.