251 pointsby CITIZENDOT5 hours ago25 comments
  • IvanGoncharov2 hours ago
    Wow, after reading this article, I figured out I was hacked, but with a way more sophisticated attack.

    A few weeks ago, I had an interview with a CTO of a totally legit company. It was weird because he had disabled the camera, and the person had a strong accent. But everything else sounded like a normal screening interview, and the person definitely knew what he was talking about. At the end of the interview, he explained to me that during the technical interview I would need to make some modifications to their project (it's an OSS product), so he asked me to clone the repo and check the setup.

    Later, the HR person said the CTO got sick, so the interview would be postponed. But a few days later, the HR profile was deleted from LinkedIn. It was super weird, but it didn't trigger my suspicion until I saw this post on HackNews. I checked, and the repo I was cloning and running during the interview had a malware payload.

    P.S. I think it was a targeted attack because in the past I maintained a very popular NPM package with 43+M weekly downloads. That's my only explanation for why someone would carry out such a sophisticated social-engineering attack against me.

    P.P.S. It's great that I have 2FA everywhere, and I always publish NPM packages manually without using tokens. But I need to wipe my laptop and reinstall everything.

    • throwatdem123117 minutes ago
      Yeah, I refuse to just clone random projects. Luckily, I’m a rails developer - and scaffolding entire applications takes literally minutes.

      Just give me the specification and I will build it end to end myself.

      If you’re serious you would consider it. If you don’t - I dodged a bullet.

      If you consider that people are using LLMs for code generation pretty much exclusively now this should be possible with any stack.

    • lathiat11 minutes ago
      Yikes.

      Going to need containerised vscode in this world.

    • pwillia725 minutes ago
      whoa
  • ericola minute ago
    Nice read, but having your home page play music is incredible rude.
  • CM3039 minutes ago
    Hmm, did anyone else have issues loading the screenshots here? I had to open most of them in a new tab to see them.

    Regardless, that's a pretty sneaky scam, and definitely something that caught out a ton of would be candidates in the past. What's more, the Visual Studio Code project mentioned in the article sounds even more horrifying. Like, the tool seriously lets you run custom code whenever someone opens your project? That feels like a really blatant malware vector that should probably have at least some sort of security mitigation...

    It's also rather worrying how little these job sites are doing about scams like this too. I get it, it's perhaps a bit difficult to catch out all kinds of wrongdoing here. But you'd think it'd be simple enough to restrict accounts from claiming to be associated with a company or organisation if there's no proof they work there. At the moment, you can basically claim to work for any company you like, or that you have any type degree from any institution under the sun. If this was verified in any real way, and messages had a large warning at the top if the original claiming to be from an organisation wasn't confirmed to work there, a lot of scams would far more difficult to pull off.

  • wxw4 hours ago
    > They embedded a script that checks the victim’s host operating system and silently executes a remote payload.

    Seems like this is becoming a recurring theme, similar story was on the front page last month.

    https://news.ycombinator.com/item?id=48546294

    • 4 hours ago
      undefined
    • gowld2 hours ago
      The OP says as much, and links to a Google Search results that says the same.
  • ivanjermakov3 hours ago
    > Why use a raw IP address? If anything, this screams “malware.”

    If the victim is deep enough to check hook's content, it's unlikely they will just stop here losing suspicion. I'm sure most devs wouldn't think that doing `git commit` can be malicious (git security oversight?).

  • vardalab2 hours ago
    My takeaway from this was that Claude was being completely useless as a helper Thanks to all the safety safeguards and that nonsense.
  • mtlynch16 minutes ago
    > Naturally, the next move was pivoting from defense to offense. I wanted to see if the attackers left any vulnerable services exposed on their IP.

    Why not attack them through the C2 interface? That's where I'd expect them to slip up.

  • darth_avocado3 hours ago
    If LinkedIn actually cared about preventing scams, they could implement verification using company emails if you want to list your current employment. And if it is too much of a heavy burden, then at the minimum you should have it as an optional feature that recruiters would have to comply with, if they want to be legitimate.
    • CITIZENDOT3 hours ago
      > they could implement verification using company emails

      they added this back in 2023 (https://news.linkedin.com/2023/april/linkedin-s-new-verifica...), but very less people actually bother to verify with their email, so not having it doesn't always mean it's illegitimate.

      • darth_avocado3 hours ago
        The legitimate recruiters should start using it then.
    • burningChromean hour ago
      Myself and my friends have for years created fake profiles to catfish recruiters and companies to find out what job reqs they have open and what they're looking for in a candidate. When JS frameworks got huge, it was really helpful to separate the legit companies and recruiters from the scammers.

      I would imagine a lot of what went on then, is going on now with all the AI jobs and demand for people who have even a cursory knowledge of LLM's and automation.

  • nphardon4 hours ago
    always a good day when we get an a post on front actually related to hacking on hackernews.
    • CITIZENDOT8 minutes ago
      thanks!
    • ivanjermakov3 hours ago
      Except hackernews is about different kind of hackers.

      http://www.catb.org/jargon/html/H/hacker.html

      > 1. A person who enjoys exploring the details of programmable systems and how to stretch their capabilities, as opposed to most users, who prefer to learn only the minimum necessary. RFC1392, the Internet Users' Glossary, usefully amplifies this as: A person who delights in having an intimate understanding of the internal workings of a system, computers and computer networks in particular.

      > 2. One who programs enthusiastically (even obsessively) or who enjoys programming rather than just theorizing about programming.

  • lantry3 hours ago
    > Side note: Why use a raw IP address? If anything, this screams “malware.” At least register a decoy domain like lint-checker.com or jenkins-ci-runner.net. If the threat actors who wrote this are reading: take notes people!

    Maybe they don't want to give any identifying info to the domain registrar? Or just minimizing their online presence?

    • HPsquared3 hours ago
      That's probably the reason bare IP addresses are associated with sketchy stuff.
    • cromka2 hours ago
      Or possibly these hosts fell victims of their malware, too, and see now used as proxies.
    • CITIZENDOT3 hours ago
      fair point
  • ge964 hours ago
    There was a funny video I saw recently someone's running Red Star OS on their computer and a scammer is trying to scam them thinking it's Windows

    Unrelated to this git pre commit hook attack but yeah

  • ChrisMarshallNY4 hours ago
    I assume these types of things are going to become more and more common.

    Looks like these folks really did their homework.

    It's nasty, but I have to respect their skills. I'll bet it works, quite often.

    • CITIZENDOT4 hours ago
      yea, i had fun looking around, this felt like a ctf challenge lol. if they had any vuln on their server, it would've been even better.
    • LoganDark4 hours ago
      Their "skills" might just be borrowed from some LLM.
      • ChrisMarshallNY4 hours ago
        I dunno. The Norks seem to be really good at this, and have been, for a long time.

        I suspect it's clever, experienced, engineers, leveraging LLMs.

      • throw_m2393394 hours ago
        Yeah, this scam is probably all automated at first place. Welcome to the "agent era"...
  • syntaxing2 hours ago
    That was a fun read, I wonder if vscode would still load the script if you click “don’t trust author”? That being said, can you embed something yourself and push the commit?
    • CITIZENDOTan hour ago
      > I wonder if vscode would still load the script if you click “don’t trust author”

      It doesn't. VSCode dev replied here on it here: https://news.ycombinator.com/item?id=46719712.

      But, I don't think anybody pays attention to the workspace trust. When ".vscode" has launch commands, it should rather say, "Trusting this workspace runs the following command on your behalf" or something similar.

  • gtowey4 hours ago
    My takeaway from this is that I should use the same defense as when someone calls you "from you bank". When they reach out directly, go to the real company's site to apply and contact a real recruiter. If you can't validate that the business is legit before, then assume malfeasance.
    • technion4 hours ago
      Companies make this hard, a bit like various email scams where legit company communication comes from seemingly random domains (hello paypal). Often the company is legit, but theres no public contact that knows anything about the recruiter thats working for them.
      • bombcar4 hours ago
        Healthcare companies are the WORST at this - they will send you legitimate email from h34lthc4re.biz with a heart-happy-health.phishing.info link that you HAVE to use - and it's all legit.
    • paxys4 hours ago
      Even if the attempt is legit, going to the company’s website/careers page to try and reach them is pointless. You application will just get lost among the thousands of others. Your best bet is to ask the recruiter to email you and check for a @<company.com> email address. And even if the attempt checks out don’t run untrusted code on your machine.
    • 4 hours ago
      undefined
    • yieldcrv4 hours ago
      it was in this moment, that gtowey’s outdated job solutions transitioned them from unc to boomer
      • gtowey3 hours ago
        I think you misunderstood.

        I'm not talking about switching to cold contacting companies as a job hunting strategy. I'm saying if you get a suspicious outreach from a rando on linked in on behalf of a company THEN you only continue if you can reach out to the same person via official company channels.

  • fitsumbelay2 hours ago
    TIL about tree ...

    I stopped being surprised by new stuff I learn about an OS I've been using for 25+ and 10+ as my daily whip and just enjoy the discovery-buzz

    these take-home interview nightmare stories are so common ... I'd hate to see a bad actor take advantage by offering a "service" to unsuspecting and underinformed folks like ... erm ... me

    • 2 hours ago
      undefined
  • iamcreasy44 minutes ago
    Interesting read. Is docker sandbox a solution in this situation?
  • drnick13 hours ago
    Are these kinds of tests still relevant in the AI age? Genuine question, I have not interviewed for a very long time. They seem as useful as take home college exams.
    • CITIZENDOTan hour ago
      It's either leetcode style interviews or take-home assessments AFAIK
  • 2 hours ago
    undefined
  • luciana1u2 hours ago
    at some point companies will realize they can just post all their backlog as take-home assignments and eliminate the engineering department entirely
  • tclancy2 hours ago
    Had something similar but less dangerous recently: I “won” a month’s subscription to a brand new “high paying, not on the public sites” job board where if I wrote a cool integration I would make a bunch of money (except the fine print said they could just take it). It took about a minute and a half of playing with the API to see they hadn’t even bothered to fully trim the listings they scraped from other sites. Each job application required you to answer a fairly detailed engineering issue. Best I could tell is they stole your answer, applied to the gig and then did one of those bait and switch interviews with the actual company.
  • pudgywalsh2 hours ago
    Did no one else read far enough to see this was a DPRK (Best Korea) APT campaign?
  • 4 hours ago
    undefined
  • sailfast3 hours ago
    Really hate that the USG overreaction on Fable has given us a neutered version of AIs for DEFENSIVE capabilities even when we just want an explanation of what we’re being subjected to with this malware.

    Give defenders a better shot…

  • rdksu4 hours ago
    Bruh the harry potter theme song scared the shit out of me as it turned itself on. Bad UX for a personal site. Great article btw !
    • ladybro4 hours ago
      Where can one be whimsical and fun if not for a personal site?
    • CITIZENDOT4 hours ago
      sorry, i added it to set the mood for my site :') yk, like moving lamps at the top, hanging dementor at the right side (only visible on desktops).

      should i remove it?

      • seanobannon4 hours ago
        absolutely not! it is a delightful source of whimsy on an increasingly uniform web
      • Lammy4 hours ago
        Middle ground: make it respect `prefers-reduced-motion` :)
      • projektfu3 hours ago
        No, it's your playground. My podcast was talking about the music the guest was making and I thought he was playing something Potter related.
      • eightysixfour4 hours ago
        No, it made me laugh.
      • Quarrelsome3 hours ago
        NEVER PURGE YOUR WHIMSY.
      • john_strinlai4 hours ago
        >should i remove it?

        there is no place for fun, whimsy, moods, or personalization on the web. sorry.

        (no, at least not at the request of random internet stranger #10545346)

        • ChrisMarshallNY3 hours ago
          Around here, many people have their sense of humor, removed, during their first colonoscopy.

          I joke, anyway, and bear the downvotes. Totally worth it.

      • aftbit3 hours ago
        I used developer tools to delete the dementor, then I muted the site when it started playing music.
      • girvo3 hours ago
        Nah, it's fine! I just muted the tab, no big deal
      • busymom03 hours ago
        Nah, keep it. It's your site and that's where you get to have fun!
      • ikistuach4 hours ago
        yes
  • wslh3 hours ago
    I assume an standard way to do this is through a VM provided by the recruiter, right?
    • simoneree2 hours ago
      I don't think you should trust the recruiter's VM any more than their code. Spin up instead your own disposable VM or container with no creds or host mounts.

      Clearly, judging by recent openai news, sandboxes are not unbreakable, but at least there's nothing worth stealing and you throw it away afterward.

      • wslhan hour ago
        I assume a VM that is running in the cloud will be enough. Not thinking about a local one.
    • CITIZENDOT2 hours ago
      yea, i'm just lazy