I Inspected My Take-Home Interview Project. It Was a Whole Operation.
Recruitment scams often use high-pay lures and legitimate-looking technical assessments to deliver malware.
Key Points
- The scam began with a LinkedIn outreach offering a remote Python developer role with an unusually high monthly salary (15,000), leveraging the prestige of a Y Combinator startup to establish fake legitimacy.
- The attack vector involved a take-home assignment delivered via a Google Drive zip archive containing a cloned FastAPI project.
- Malware was embedded in the
.git/hooks/pre-commitscript, which detected the host OS (macOS, Linux, Windows) and executed a remote payload from a raw IP address. - The multi-stage payload installed Node.js and executed an obfuscated
parser.jsscript. The associatedpackage.jsonincludedhardhat(an Ethereum development environment) andclipboardy, strongly suggesting the intent was to drain crypto wallets or steal sensitive clipboard data. - Other variants of this campaign use
.vscodefolder launch commands to infect users simply by opening the directory in VS Code, bypassing the need to run Git commands.