Discussion summary

A LinkedIn job offer was found to contain a backdoor, raising concerns about scams and security risks. Users discussed the prevalence of malicious offers and skepticism towards LinkedIn as a recruitment platform.

What the discussion says

  • Many users express distrust of LinkedIn due to scams.
  • Some suggest avoiding installing software from suspicious offers.
  • There is a call for better security tools for developers.
“LinkedIn has become a rotten cesspool of scammers and spammers.”
— kuyawa
“There is a market for an 'antivirus for developers'.”
— harrouet

Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • They seem to using the same domain for multiple targets: reddit thread from 3 months ago:

    https://www.reddit.com/r/openclaw/comments/1rlet0h/someone_t...

  • This is uncomfortably close to a normal interview task now.

    Someone sends you a repo, says the install is broken, and asks you to take a look.

    A lot of developers would run rpm install before thinking twice, especially if they were tired or looking for work.

  • Job candidates keep facing a lot of hurdles, including scams, Trojan horses like the one presented here, ghosting, wasting candidates' time, nepotism, etc. As a candidate you can easily spend more than 8 hours a day looking for opportunities, switching stacks, studying, doing take-home projects, etc, for absolutely nothing. Life is precious and shouldn't be burned like that!
  • > I reported the repo to GitHub and the recruiter to LinkedIn. So far nothing has changed and the code is still up.

    Oh, Microsoft.

  • This type of attack has been happening a lot the past 2 years. I've seen one that was very well done...the GitHub account of a fairly well known security researcher had been compromised...their identity and code was being used as part of the recruitement. I reached out to the person...who was understandably embarrassed and told me they had reported this to LinkedIn + Github but saw no action.

    This is the part that really irks me: LinkedIn and Github know this is the end goal of many of the rampant supply chain attacks but they a) don't have a first class mechanism for reporting b) don't seem to be improving their systems or even warning people. I have been hit be this enough times that I follow along to get screenshots of the scammer. One might think with all the surveillance systems Microsoft/LinkedIn/Github/Google-Meet/Calendly have in place that a potential victim reporting it along with an actual picture of the scammer could get us somewhere.

  • The difference between pre- and post-chatbot writeups is stark: https://igor-blue.github.io/2021/03/24/apt1.html

    $100 says OP is Claude

  • So, this is a crime right? Why isn't there a well known '911' for cybercrime to report things like this to and get help? Society needs to catch up with the actual dangers out there and build support networks for this ASAP. This is organized crime and needs organized defense to deal with it.
  • > a recruiter at a small crypto startup [...] she described a broken proof-of-concept they needed a lead engineer for, and then sent me a public GitHub repo to review. Specifically, she asked me to “check out the deprecated Node modules issue.”

    > ...buried between walls of commented-out tests, the payload runs anything the server sends back to your machine.

    > npm runs prepare automatically after npm install, so just installing dependencies executes the backdoor.

    > The instruction to “check out the deprecated Node modules issue” was bait to get me to run npm install.

    Great catch. I've not been phished on LinkedIn before. Surprised it's getting this bad.

    by wxw

Explore Birbla archives