A stranger messaged me on LinkedIn about a job in the Web3 space. Friendly, low pressure, said it sounded like a good fit. To show me what the team was building, they shared a private GitHub repository and asked me to spend "15 to 30 minutes running it and looking around" to see whether the project made sense to me.

That repository was not a job assessment. It was a trap designed to steal from the developer who runs it. Here is what it actually was, how it works in plain language, and the red flags that let you spot this without being a security expert.

The short version

The repo looks like a real, working crypto staking app. Most of it genuinely functions. That is the whole point: it needs to be convincing enough that you clone it and run it.

Hidden inside is a single booby-trapped file, disguised as a harmless styling plugin. The moment you run or build the project on your own machine, that file executes as a program with full access to your computer. It then quietly: