relay.lc Job Scam Delivers Info-Stealing Malware Targeting Web3 Wallets

SlowMist/MistEye reports a job-scam operation using the site relay.lc to trick Web3 professionals into installing “interview software.” The lure claims to be an AI meeting and collaboration platform (via Windows/macOS download pages), but the installers are designed as an info-stealing malware chain. On macOS, the DMG contains no legitimate .app. Instead, a script launched via “drag into Terminal and press Enter” copies a hidden executable, removes macOS quarantine attributes, and then collects highly sensitive data. The malware prepares candidate passwords and reads the user’s macOS login Keychain database, combining the candidate password with Keychain contents into a network request. It also targets browser data (passwords, cookies, tokens), wallet-related extensions (MetaMask, Phantom, Trust Wallet), Telegram Desktop session data, and Apple Notes. No reboot-persistence was found. On Windows, the Electron-based installer shows a fake “Updating” progress bar. The progress logic is randomized and not tied to real installation activity. When the bar hits 80%, it triggers a runUpdate routine that launches an unsigned updater.exe via PowerShell with administrator privileges (UAC elevation, hidden window). The embedded component attempts reboot persistence through Run/RunOnce/Startup folder, then scans Chrome/Brave extension process memory for wallet unlock parameters, and exfiltrates results to e1.cdnresolver.com (with additional telemetry via Sentry). IOCs include relay.lc and cdnresolver.com domains, and multiple sample hashes (Relay.dmg, Relay.exe, updater.exe, etc.). MistEye flags relay.lc as high-risk and recommends immediate isolation, credential rotation, session revocation, and—if Windows execution is confirmed—reinstalling the OS.
Neutral
This is a cyber/identity theft event targeting Web3 professionals rather than a protocol upgrade, token emission change, or exchange/market microstructure event. So it is unlikely to create direct, sustained market-wide fundamentals impact. However, it can produce localized bearish pressure and short-term volatility in affected communities: (1) successful credential and wallet unlock theft can lead to user sell-offs, (2) growing incident reports increase perceived smart-wallet and operational risk, and (3) firms may reduce Web3 engagement after such attacks. Historically, similar “credential-steal + wallet-drainer” campaigns (e.g., fake support links, fake updates, or malicious installers) typically cause short bursts of fear and capital re-allocation toward safer custody practices, but markets often revert once wallets are drained/blocked and follow-up security actions (session revocation, asset migration, domain takedowns) begin. Net: neutral for broad market stability, but watch for short-term sentiment dips among Web3 traders who monitor wallet-extension compromise narratives.