Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Slop article. Good for scam awareness I guess, but the main value of the analysis and advice is comedy.

    > read process.env directly, which in this app means MONGO_URI, JWT_SECRET, SENDGRID_API_KEY, CLOUDINARY_API_SECRET, PAYTM_MERCHANT_KEY

    yeah it can run arbitrary malicious code, but let’s also highlight that it can read the fake app’s own dummy environment variables

    > When the victim connects out to […], the server sees the source address on the accepted socket, exactly as any web server sees a visitor’s IP. No discovery, no scanning, no registration of an address. This is precisely why outbound-only design is so convenient for the attacker: it works behind NAT, CGNAT, a corporate proxy, or a home router with zero configuration, and it doesn’t matter if the victim’s IP changes.

    huge

    > If there is no UI/Desktop environment the module for leaking browser data or screenshots is self-limiting.

    yeah this is why a VM is important, it’s because it doesn’t have a UI so screenshots don’t work

    > … and reinstall your OS - better safe than sorry.

    yeah just for thoroughness’s sake after having a RAT installed (hopefully you didn’t do this step last)

  • Being on the job hunt myself this is very helpful! I do however prepare public repos and showcases for such interviews/applications, I hope my luck streak doesnt run out
  • The internet world really does run on trust-chaining reputation.

    A person who takes random things from a near stranger on the internet and runs it on their computer with no real safeguards is not a person I should hire.

    Which also means that your hiring practice should not involve a person you met on zoom/Teams/whatever 10 minutes ago being required to run your random crap without safeguards.

    Which means if you want them to download and run stuff, you should list the requirements so the applicant can decide if they are going to do that for you.

    But we don't live in such an ideal world....

  • Yeah but the actual employers are asking them to run random things on your computer. Often actual malware like Slack, Zoom, Teams, Google Meet. What do you expect the candidate to do? (Possible answer: use a VM)
  • > Putting things into Docker and only executing the code inside isolates your host system and does not reveal any stored secret - as long as you do not mount host data into the container.

    Doesn't mention why... Gives no similar warning about VM.

    You usually have to mount at least some data in a container or VM for it to be useful. Of course, being an idiot and sensitive mounting secrets in untrusted environment is the problem, container or VM doesn't matter.

    Maybe it means there's some 0day where mounting any volume allows container escape or something? But that's not what it says.

  • I remember reading a similar article here not long ago, and the attack relied on auto-loading in VSCode.

    https://opensourcemalware.com/blog/latest-contagious-intervi...

  • Since no one mentioned it - this seems to be a major and real problem in the crypto job space. In their job market it's more believable that a 'stealth startup' is reaching out and doing a code challenge from an unfamiliar email or repo, and crypto devs are likely to have a wallet or passwords accessible on their system. They are willing to go above and beyond the regular spam or AI conversations to get access.
  • cheap laptops are cheap, simply don't use your "real" computer.
  • Also, to be into cryptocurrency, you kind of have to be gullible to begin with.
    by fwip
  • Yes, I got targeted too: https://blog.denv.it/posts/i-was-likely-targeted-by-dprk-in-...

    (Don't work in crypto, but there's a crypto company with the same name as the one I work at)

  • There is a YC company that makes a coding interview tool. They want you to run their CLI on your machine and trust that it won't do anything malicious, when in fact it installs a bunch of things onto your machine without consent, scans processes, and intercepts requests from AI tools. It's crazy that people think this is acceptable.
  • Even more reason to use VMs.
  • Name the company
    by htrp
  • Maybe it's a pen test such that if the CLI can phone home you fail, to weed out candidates with weak security fu.
  • Just that fact that the company expects a candidate to even have their own machine is egregious.
  • My first thought after reading the article: develoepers NEED to learn to use firewalls such as LuLu(https://objective-see.org/products/lulu.html) to get interactive dialogs asking whether any given binary can access any given internet address whether it is a domain address or IP address (which can seem even shadier).

    I am an Emacs user but every time I have tried a new editor, including VS Code or VSCodium I blocked access to remote addressed which were prompted to me even though I did not neither authorize extension download nor extension download.

    I think it would have been even funny for devs trying out for code challenges while using "interactive" firewalls such as LuLu, then catching the shadiness and blocking access right up.

  • This really is the simplest path to somewhat decent security, and alongside it you may catch some programs doing requests that are fine for security but you'd rather it not do because of privacy.
  • I get enough legit and illegitimate ones every week on LinkedIn that it's become really easy to tell the difference. Hard to pinpoint in a comment because it's mostly a gut feeling. But, in rough order:

    1. Look at the person's LinkedIn profile contacting you and examine their post history. In one comical scenario the "recruiter" had a long 4 year gap where they were writing comments in English and all of the sudden they switched to Spanish. Mostly short, pointless comments as well.

    2. Look at the company and make sure they have a legitimate website and are still actually in business. Even better, see if there's a public team page that lists this person.

    3. Give the recruiter an email (I usually use something like SimpleLogin) and ask them to forward you the details. Of course, pay close attention to what address they send it from.

    4. In addition, or alternatively, ask the recruiter for the public job listing (scammers almost always "paste" it into a DM or upload a clearly AI generated PDF doc).

    Once you learn the game it's not too hard to start picking up on them. I've made it a game to play along sometimes just for fun. Ultimately, at the end of the day, make sure you report them on LinkedIn. I've had the account disappear within a hour of doing so.

  • Honestly unless I'm planning on quitting my current job, or if I were unemployed, I just ignore the linkedin.

    Sure they spam you with "XX wants to connect", or "I'm awaiting your reply" emails. But real contacts and friends can call/email you, and everybody else can wait six months.

    Despite only connecting with actual people I've worked with, not recruiters, I still get "suggested" posts which are slop, and "that happened". The site is a cesspool.

  • > “A relevant opportunity” with part-time remote work and a great hourly compensation

    That is so suspicious at the moment.

  • out of the list under "Before you start with the test, you might be suspicious about the following:" there is only one that is important:

    only interact with people using an official email address.

    the rest can be used as yellow/red flags, but simply asking for confirmation via an official email address will thwart the vast majority of scams (including other ones, like someone claiming to be from Intuit calling about your QuickBooks or whatever).

  • fter posting on the HN front page, I got way too many job scam contacts—all through Gmail, not official company emails.
  • > simply asking for confirmation via an official email address

    There are some smart new scammers who now create a lookalike domain which either redirects to the original or shows a fake corporate portal. How could a random interviewee know whether john at strinlaicorp.com is real or john.s at strinlai.net is fake?

  • > only interact with people using an official email address.

    And then google whether the domain is associated with phishing attempts. i've been targeted several times recently by folks with "official" email addresses but whose domains are (per google) strongly associated with phishing.

  • I have seen official company recruiters operate exclusively through Gmail or whatever. Third party headhunters may not have anything tied to the sponsoring company.

    It is a decent rule, but one which is immediately thwarted by companies going out of their way to constantly look illegitimate.

  • If a company is not even willing to have a real person speak to you at the start of the recruitment process, what does that say about them? Or about the legitimacy of that job posting? Or about the people you would be working with if you did get hired?

    Regardless if you get an offer or not, you will invest a significant amount of finite time in each interview cycle and if you do get an offer, you'll be investing even more time into that company.

    So no matter who you are, protect your time and remember that interviewing is always a 2-way street.

  • Are you familiar with the concept of a recruitment funnel? It is not financially worth it to personally talk with every single person that applies to a company.