A phishing campaign impersonated a real company to send software engineers a TypeScript coding challenge through LinkedIn recruitment messages. The company named in the outreach was not involved and had publicly warned about the impersonation. Warning signs included a recruiter unaffiliated with the company, no introductory call, a personal Gmail address, an unexpected programming language, and code hosted on Bitbucket. The roughly 180-file project ran a loader when candidates used commands such as npm run dev or npm start. It contacted api.jsonbin.io to retrieve obfuscated JavaScript, which then contacted a command-and-control server at 147.189.174.138. The delivered modules included a remote-access trojan with shell access, SSH pivoting, screenshot capture, clipboard monitoring, and synthetic mouse and keyboard controls; a browser credential and cryptocurrency-wallet stealer; and a file grabber. The malware targeted environment variables, SSH and cloud credentials, .env files, private keys, browser profiles, wallet extensions, and user documents. It could access these files without administrator privileges because they are normally owned by the logged-in user. The malware also checked whether it was running in a virtual machine. Running untrusted coding tests in an isolated VM and restoring a snapshot afterward can limit exposure, although malware can still steal data accessible within that VM. Suspected victims should rotate credentials and keys, assess exposed secrets, and reinstall their operating system.
codedge.de
6 min
11h ago
A phishing campaign impersonated a real company to send software engineers a TypeScript coding challenge through LinkedIn recruitment messages. The company named in the outreach was not involved and had publicly warned about the impersonation. Warning signs included a recruiter unaffiliated with the company, no introductory call, a personal Gmail address, an unexpected programming language, and code hosted on Bitbucket. The roughly 180-file project ran a loader when candidates used commands such as npm run dev or npm start. It contacted api.jsonbin.io to retrieve obfuscated JavaScript, which then contacted a command-and-control server at 147.189.174.138. The delivered modules included a remote-access trojan with shell access, SSH pivoting, screenshot capture, clipboard monitoring, and synthetic mouse and keyboard controls; a browser credential and cryptocurrency-wallet stealer; and a file grabber. The malware targeted environment variables, SSH and cloud credentials, .env files, private keys, browser profiles, wallet extensions, and user documents. It could access these files without administrator privileges because they are normally owned by the logged-in user. The malware also checked whether it was running in a virtual machine. Running untrusted coding tests in an isolated VM and restoring a snapshot afterward can limit exposure, although malware can still steal data accessible within that VM. Suspected victims should rotate credentials and keys, assess exposed secrets, and reinstall their operating system.
codedge.de
6 min
11h ago
A phishing campaign impersonated a real company to send software engineers a TypeScript coding challenge through LinkedIn recruitment messages. The company named in the outreach was not involved and had publicly warned about the impersonation. Warning signs included a recruiter unaffiliated with the company, no introductory call, a personal Gmail address, an unexpected programming language, and code hosted on Bitbucket. The roughly 180-file project ran a loader when candidates used commands such as npm run dev or npm start. It contacted api.jsonbin.io to retrieve obfuscated JavaScript, which then contacted a command-and-control server at 147.189.174.138. The delivered modules included a remote-access trojan with shell access, SSH pivoting, screenshot capture, clipboard monitoring, and synthetic mouse and keyboard controls; a browser credential and cryptocurrency-wallet stealer; and a file grabber. The malware targeted environment variables, SSH and cloud credentials, .env files, private keys, browser profiles, wallet extensions, and user documents. It could access these files without administrator privileges because they are normally owned by the logged-in user. The malware also checked whether it was running in a virtual machine. Running untrusted coding tests in an isolated VM and restoring a snapshot afterward can limit exposure, although malware can still steal data accessible within that VM. Suspected victims should rotate credentials and keys, assess exposed secrets, and reinstall their operating system.
codedge.de
6 min
11h ago
No more articles to load