SlowMist's Chief Information Security Officer, 23pds, has issued a warning about the Lazarus Group's HexagonalRodent campaign targeting Web3 developers. The group employs social engineering tactics, such as offering lucrative remote job opportunities and recruitment by prominent projects, to deceive developers into executing malicious code. This strategy aims to steal cryptocurrency assets from users. On March 9, 2026, a developer associated with a fast-draft extension was compromised by the OtterCookie malware, which facilitated the distribution of harmful programs. The attackers are leveraging tools like ChatGPT and Cursor to enhance the sophistication and believability of their schemes, posing a significant threat to the Web3 community.