Developer discovers remote code execution backdoor hidden in fake crypto startup job offer on LinkedIn
By
lwhsiao
Crispy enough to crunch, soft enough to enjoy. A good bake.
Summary
A security-conscious developer receives a LinkedIn job offer from a recruiter at a crypto startup. Suspicious of the request to review a GitHub repo's "deprecated Node modules," the developer spins up a throwaway VPS instead of cloning locally. Upon investigation, they discover a hidden remote code execution (RCE) payload embedded in a test file within the repository — a sophisticated backdoor attempt disguised as a legitimate job screening process.
Key quotes
· 3 pulledInstead of cloning and installing dependencies, I spun up a throwaway VPS on Hetzner, cloned the repo there, and...
Something felt off and raised an alarm in my head, so I decided to get a bit extra paranoid.
She described a broken proof-of-concept they needed a lead engineer for, and then sent me a public GitHub repo to review.
You might also wanna read
North Korean Hackers Target Developers via GitHub with Fake Recruitment Lures and Malicious VS Code Projects
Researchers have uncovered UNK_DeadDrop, a North Korea-linked phishing campaign that targets developers on GitHub using fake recruitment and
hendryadrian.com·1d agoCritical Gogs RCE bug (CVSS 9.4) remains unpatched; exploit module now public
A critical remote code execution (RCE) vulnerability rated 9.4/10 has been discovered in Gogs, a popular open-source self-hosted Git service
North Korean-linked phishing campaign targets developers with fake job offers to steal cryptocurrency
A suspected North Korean-linked phishing crew sent over 250 fake developer job pitches to employees at nearly 100 organizations (mostly US-b

GitHub patches critical remote code execution vulnerability in under six hours after AI-assisted discovery
GitHub patched a critical remote code execution vulnerability in under six hours last month. The flaw, discovered by Wiz Research using AI m
Fake ChatGPT and Claude installers on GitHub and SourceForge deliver Deno RAT malware that steals crypto wallets
Attackers are distributing counterfeit installers for popular software like ChatGPT, Claude, AutoTune, Kontakt, Ableton Live, and ZENOLOGY o
