Spacelab
TECH CREATORS FESTIVALS  MUSIC
GEAR AI SOCIAL MEDIA GUIDES

CYBER SECURITY

SPONSORSHIP
 
     
     
 
 

Hackers Are Turning Google Apps Script Into a Malware Trap for Crypto Job Seekers

 

Google Apps Script is being abused in a targeted malware campaign that turns a fake Web3 job interview into a Google-hosted trap for crypto workers.

 



The unsettling part is how normal the setup looks right up until the “technical assessment” quietly starts deciding what kind of malware the victim should receive.

➜ The real story: Attackers aren’t just cloning trusted brands anymore. They’re building the lure inside legitimate cloud infrastructure, mixing real Google pages, signed Windows software and personalized recruiting tactics into one very convincing chain.

 



How the Google Apps Script Web3 Job Attack Profiles Crypto Targets

 

The attack begins with a fake recruiter contacting a cryptocurrency employee who was publicly looking for work, then moving the conversation through LinkedIn, Calendly and what appears to be a Google Sheets assessment.

 

The assessment is actually a Google Apps Script web app that can collect an IP address, approximate location, ISP, browser, operating system and signs of installed crypto wallet extensions before the victim downloads anything.

 

That profiling gives the operator a much clearer picture of who clicked, what device they’re using and whether the target is worth pushing further.

 

Why Signed Microsoft ClickOnce Malware Makes the Google Lure Look Legit

 

On Windows, the fake assessment eventually produces a fabricated connector error and offers a supposed Google API helper.

 

The download is a signed Microsoft ClickOnce application called GapiUpdate.application, which makes the installer look more legitimate than a random executable from an unknown publisher.

 

Once launched, it can show a real Google Workspace Marketplace page through WebView2 while malicious staging activity happens in the background.

 

It’s a strong example of why a familiar logo, a Google-hosted page or even signed software shouldn’t be treated as automatic proof that a download is safe.

 

The Google Apps Script Malware Chain Can Steal Crypto Keys, Passwords and Developer Credentials

 

The next stage pulls down a password-protected archive containing three Windows executables disguised as PNG images.

 

Those payloads include NeedleStealer, a separate Rust-based information stealer and a Go remote-access trojan with keylogging, file-management, proxy and hidden-VNC capabilities.

 

The malware can reach far beyond crypto wallets into browser sessions, password managers, developer credentials, cloud configurations and other secrets stored on the computer; in the documented incident, private keys were compromised and assets were removed across six blockchains in roughly an hour.

 

The broader lesson is to treat unexpected “helpers,” “connectors” and “updates” as a hard stop, especially after reading how phishing and social-engineering attacks exploit trusted workflows, how real personal details can make phishing scams more convincing, and how new AI cybersecurity tools are giving defenders faster ways to investigate advanced threats.

 

FAQs

What is the Google Apps Script malware attack?

It’s a targeted social-engineering campaign that uses a fake Web3 recruiting process and a malicious Google Apps Script web app to profile victims before delivering credential-stealing malware and a remote-access trojan.

Was Google Apps Script hacked?

No evidence shows that Google Apps Script itself was breached. The attackers abused legitimate Google-hosted infrastructure to make a malicious assessment and download flow look trustworthy.

How can crypto workers avoid fake Web3 job malware?

Be suspicious if a recruiter or assessment asks you to install a helper, connector or update. Verify the request through a separate channel before running software, even when the page looks legitimate or the installer is digitally signed.

 

 
 
 
     
     
 

 

 
 
Spacelab

Tech, Music, and Creative Culture

A Home for Independent Thinkers

 
Independent and built for discovery. It’s not just about covering the news—it’s about shaping the conversation.
 
Creative Commons Copyright, 2025. Some Rights Reserved.
Spacelab is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License. MORE >
         
FESTIVALS NEWS STORE CONNECT SPACELAB
USA TECH AMAZON FACEBOOK ABOUT
CANADA CREATORS ETSY INSTAGRAM CONTACT
UK     TWITTER ADVERTISE
AUSTRALIA     RSS PRIVACY
EUROPE       ETHICS
ASIA       FTC DISCLOSURE
2025       SEARCH
2026