Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Why is npm still not blocked by every OS on earth is beyond me. These guys will never learn.
  • npm is hard to avoid, as other ecosystems have integrated it as a cross-platform build/installer script bootstrap.

    Indeed, all things nodejs are usually a dumpster fire at a hair salon, but the real point here was people always inherit whatever the previous cheapest labor built at that office. Also, usually people don't get to make architectural decisions for a long time. =3

  • Because uh every OS on earth has the exact same vulnerabilities? How are you supposed to stop a user from downloading something random from the internet and running it?
  • How does npm differ from any other package manager in that sense?
  • fyi npm 12 will have securer defaults https://github.blog/changelog/2026-06-09-upcoming-breaking-c... but it will be a while for ecosystem to catch up and npm reputation already damaged
  • Nothing to do with nom itself. This sort of scam would have worked with many different technologies, even a Makefile.
  • Been through this 3 times in the last 6 months. They're getting better. Very credible LI profiles, code looks OK if you only take a glance... The bell start ringing when they insist you to run locally their sh*t
  • The big red flag should be giving github access before signing any contracts.
  • Similar for me. One was for an overly very well paid position. I always run (p)npm audit before running npm repos, so lots of issues were found. I tried to fix them but I would have gone over the time limit. So I asked the recruiter about it and if it makes sense to run it in an isolated VM. No answer...

    The other was for a DevEx crypto service. While I was very suspicious the code looked okay but the recruiter was strange and changed their profile to a different person eventually. I think this was a crypto stealing scam though since it required connecting to a wallet. I don't have any crypto though, so I might be okay for now. Although reinstalling my system clean would be the only sure way in theory...

  • Im not sure if anyone will read this, but I consider myself pretty savvy having been on the internet over decades however I nearly succumbed to a highly complex Linkedin "Interview with video call just to get me to install malware".

    It was the most bizarely long roundabout way to get me to isntall malware I had ever witnessed I couldnt fathom it was real, I mean they interviewed me for half an hour. Now you might think Im paranoid however it was obvious, their camera was off ( personal preference they said) and well I allowed it... only for other eventual straws to breal the camels back, and I realised "oh uh oh this is just 2 strangers trying to get me to install crap on my laptop for wealth extraction".

    I was flumoxed tbh I couldnt believe it, as the approach had been very organic, through Linkedin Dms, just that eventaully I realised I had succumbed to "yes men" ( the only thing that would get passed my already strict job filters ironically) to allow myself into such a comprimising situation.

    The only question I had is how did they do such a smooth complex manouver and then I realised... oh they just used AI to come up with the plan and implementation.

  • Yeah, the camera off thing has happened to me too, and it should be a red flag to anyone if an interview situation.
  • Maybe Mac will finally get decent virtualization framework. Downloading random unprotected scripts from internet, like it is 1995 is getting old pretty fast.

    Remember to use protection when meeting random people, and putting their junk deep inside your computer!

  • >Downloading random unprotected scripts from internet, like it is 1995 is getting old pretty fast.

    It's ok, the guy with glasses from the Daily Show said it's ok.

  • > Maybe Mac will finally get decent virtualization framework.

    it already has, you can configure intellij to run npm commands in a Docker container.

  • Or running random curl | bash scripts from GitHub, AUR, NPM are just as bad but many developers here still have dubious assumptions on this bad practice.

    The last few weeks tell us how bad this is especially with all the mini-shai hulud's running around.

    by rvz
  • They seem to using the same domain for multiple targets: reddit thread from 3 months ago:

    https://www.reddit.com/r/openclaw/comments/1rlet0h/someone_t...

  • This is uncomfortably close to a normal interview task now.

    Someone sends you a repo, says the install is broken, and asks you to take a look.

    A lot of developers would run rpm install before thinking twice, especially if they were tired or looking for work.

  • The interview context makes it worse. You’re trying not to look slow, so you skip the part where you ask whether you should run it at all.
  • Job candidates keep facing a lot of hurdles, including scams, Trojan horses like the one presented here, ghosting, wasting candidates' time, nepotism, etc. As a candidate you can easily spend more than 8 hours a day looking for opportunities, switching stacks, studying, doing take-home projects, etc, for absolutely nothing. Life is precious and shouldn't be burned like that!
  • It is absolutely the worst. Also the feeling that this task of job searching is supremely important. You feel guilty doing anything that isn’t job searching. Meeting friends? Spending money while you aren’t making any? Seems irresponsible internally. When your day fills with stuff that isn’t job searching it makes you feel that day was a failure. Even when you do job search and you have say a month without any bites, it also makes you feel that month was a failure. You feel like you are wasting your life. At least when you had a job, that time spent counted for a little more experience. Every second without a job feels like it counts against you. You feel like a leper. Look at me who failed to secure a job, I must be a failure, you think internally.
  • > Life is precious and shouldn't be burned like that

    Very true. I remember when I was job hunting fot 2 years post-graduation, that these time sinks started to take meaning away from life and induced cynicism and depression (to an extent).

    It's easy to forget all that once you end up getting a job, but remember to always be human and show empathy if a person cold-reaches out to you.

  • > I reported the repo to GitHub and the recruiter to LinkedIn. So far nothing has changed and the code is still up.

    Oh, Microsoft.

  • Same story for me. I gave them the repo link and messages. Nothing 2 weeks later. Now I just block them and even then, you can't select a proper reason (there's no "other" field for a block), so I just say they're impersonating someone and leave it at that. We cannot let this become the primary site for job postings.
  • They should have reported it for DMCA violation. It would be gone instantly.
  • Weird, isn't it? Microsoft owns all of LinkedIn, Github and NPM.

    All three either have security or stability issues, which seems to get worse, not better, as microsoft goes more into AI. Where is the AI productivity (10x by some accounts!) within the company going to?

  • I once saw an ad on LinkedIn made up to look like the CBC (Canadian news) linking to a fake video of the Canadian prime minister announcing a crypto investment plan for all Canadians, with a link to sign up. I reported the ad to LinkedIn and shortly after got a reply telling me they investigated and didn’t find any violation of their policies.
  • This type of attack has been happening a lot the past 2 years. I've seen one that was very well done...the GitHub account of a fairly well known security researcher had been compromised...their identity and code was being used as part of the recruitement. I reached out to the person...who was understandably embarrassed and told me they had reported this to LinkedIn + Github but saw no action.

    This is the part that really irks me: LinkedIn and Github know this is the end goal of many of the rampant supply chain attacks but they a) don't have a first class mechanism for reporting b) don't seem to be improving their systems or even warning people. I have been hit be this enough times that I follow along to get screenshots of the scammer. One might think with all the surveillance systems Microsoft/LinkedIn/Github/Google-Meet/Calendly have in place that a potential victim reporting it along with an actual picture of the scammer could get us somewhere.

  • Call it a conspiracy theory, but I think a lot of these businesses actively avoid making serious efforts because even trying creates expectations. Ones that they don’t want to be on the hook for.

    Like the Facebook problem. They were never in more trouble with people and legislators than when they were spending mountains of gold trying to police content.

    It’s much easier to shrug and say, “Sorry folks, it’s the internet. Good luck.”

  • The difference between pre- and post-chatbot writeups is stark: https://igor-blue.github.io/2021/03/24/apt1.html

    $100 says OP is Claude

  • nice! i fell for it..