How to compromise your system with a job interview

95 points - today at 3:50 PM

Source

Comments

john_strinlai today at 4:27 PM
out of the list under "Before you start with the test, you might be suspicious about the following:" there is only one that is important:

only interact with people using an official email address.

the rest can be used as yellow/red flags, but simply asking for confirmation via an official email address will thwart the vast majority of scams (including other ones, like someone claiming to be from Intuit calling about your QuickBooks or whatever).

forinti today at 5:46 PM
> “A relevant opportunity” with part-time remote work and a great hourly compensation

That is so suspicious at the moment.

mapmeld today at 7:39 PM
Since no one mentioned it - this seems to be a major and real problem in the crypto job space. In their job market it's more believable that a 'stealth startup' is reaching out and doing a code challenge from an unfamiliar email or repo, and crypto devs are likely to have a wallet or passwords accessible on their system. They are willing to go above and beyond the regular spam or AI conversations to get access.
dprkh today at 5:07 PM
There is a YC company that makes a coding interview tool. They want you to run their CLI on your machine and trust that it won't do anything malicious, when in fact it installs a bunch of things onto your machine without consent, scans processes, and intercepts requests from AI tools. It's crazy that people think this is acceptable.
zuuna today at 6:38 PM
Being on the job hunt myself this is very helpful! I do however prepare public repos and showcases for such interviews/applications, I hope my luck streak doesnt run out
aliasxneo today at 4:13 PM
I get enough legit and illegitimate ones every week on LinkedIn that it's become really easy to tell the difference. Hard to pinpoint in a comment because it's mostly a gut feeling. But, in rough order:

1. Look at the person's LinkedIn profile contacting you and examine their post history. In one comical scenario the "recruiter" had a long 4 year gap where they were writing comments in English and all of the sudden they switched to Spanish. Mostly short, pointless comments as well.

2. Look at the company and make sure they have a legitimate website and are still actually in business. Even better, see if there's a public team page that lists this person.

3. Give the recruiter an email (I usually use something like SimpleLogin) and ask them to forward you the details. Of course, pay close attention to what address they send it from.

4. In addition, or alternatively, ask the recruiter for the public job listing (scammers almost always "paste" it into a DM or upload a clearly AI generated PDF doc).

Once you learn the game it's not too hard to start picking up on them. I've made it a game to play along sometimes just for fun. Ultimately, at the end of the day, make sure you report them on LinkedIn. I've had the account disappear within a hour of doing so.

vlod today at 6:29 PM
I've been meaning to learn/run QEMU on my linux box. I assume I don't need to do anything apart from rebuild the image each time I need to do this?

Yes I most likely will tell them to get lost, but if I get an invite from Larry/Sergey I want to be ready.

pronoiac today at 5:29 PM
If you run across something like this:

* perhaps archive your findings

* report the abuse to their hosting

I'm dropping emails to jsonbin.io and to ZapHosting (who run 147.189.174.138) about this.

sorokod today at 7:41 PM
A recruiter recently sent me an "I'd like you to explore..." email. Every "further info" link in it pointed to znsrc.com/[unique_id] rather than to the displayed address.

That felt dishonest and I ignored the email.

Terr_ today at 7:55 PM
> It never asks for elevation. It doesn’t need root, UAC, or sudo, because nothing it wants is root-owned. SSH keys, AWS credentials, browser profiles, wallet data, .env files - all of it is user-owned by design, because you need to read it routinely.

Tangentially, what have people found that works well in term of hardening [0] desktop linux? For example, at least keeping "banking" separate from code-development?

I figure the only good way to keep separate user accounts and whenever I have to do something as root, I switch to the most-secure and least-used of the accounts.

[0] https://xkcd.com/1200/

nottorp today at 7:38 PM
> The code is available on Bitbucket, which IMHO is uncommon

What? There is no world outside github?

The rest of the article is legit, but they had to insert some monopoly worship...

Kuyawa today at 7:22 PM
I received so many of these requests to install malware that I removed linkedin from my life completely (besides the scam and spam flood)

Do not install anything on your machine, ever. Tell them politely ~to fuck off~ that you are not interested and move on. I know the desperation to be jobless will obfuscate your mind but again, never ever install anything on your machine when job hunting. I've seen people lose their crypto savings in seconds to say the least.

You've been warned.

sandeepkd today at 4:14 PM
These seem like a common pattern lately. I feel for it but again people are creative in making business out of others desperation.
sixtyj today at 5:17 PM
It reads like a true crime story.

Bad actor had prepared the set up so precisely that Claude Code could not detect it.

Malware Bytes? Acronis? There must be some template…

NalNezumi today at 4:59 PM
.... Why would you do job interview when they expect you to run some code on your own system, on your own time?

Maybe I work in a different field but last year when I was still looking for jobs, only one company asked for coding assignment and every other company did coding interview which is always browser based editor.

I feel like the industry is mature enough that you can tell a company that sends you a zip file of code to f-off.

esafak today at 4:08 PM
I remember reading a similar article here not long ago, and the attack relied on auto-loading in VSCode.

https://opensourcemalware.com/blog/latest-contagious-intervi...

zuzululu today at 4:27 PM
wonder if codex can catch issues ?

> A note on the AI part: Claude Code was not able to detect any strange things when just prompted to scan the code base for unusual patterns.

akarshhegde18 today at 7:24 PM
[flagged]
minitech today at 6:11 PM
Slop article. Good for scam awareness I guess, but the main value of the analysis and advice is comedy.

> read process.env directly, which in this app means MONGO_URI, JWT_SECRET, SENDGRID_API_KEY, CLOUDINARY_API_SECRET, PAYTM_MERCHANT_KEY

yeah it can run arbitrary malicious code, but let’s also highlight that it can read the fake app’s own dummy environment variables

> When the victim connects out to […], the server sees the source address on the accepted socket, exactly as any web server sees a visitor’s IP. No discovery, no scanning, no registration of an address. This is precisely why outbound-only design is so convenient for the attacker: it works behind NAT, CGNAT, a corporate proxy, or a home router with zero configuration, and it doesn’t matter if the victim’s IP changes.

huge

> If there is no UI/Desktop environment the module for leaking browser data or screenshots is self-limiting.

yeah this is why a VM is important, it’s because it doesn’t have a UI so screenshots don’t work

> … and reinstall your OS - better safe than sorry.

yeah just for thoroughness’s sake after having a RAT installed (hopefully you didn’t do this step last)