| |
A backdoor in a LinkedIn job offer
A developer received a suspicious LinkedIn job offer from a recruiter asking him to review a GitHub repository, which contained a hidden backdoor that would execute when `npm install` was run during setup. The backdoor was disguised in a test file and designed to execute arbitrary code from a remote server; the developer discovered it by using a read-only AI agent to review the code instead of installing it directly. The attack used stolen identities of a real developer and an arts journalist, demonstrating how such supply chain attacks can target engineers through social engineering.
Read Full Article →
← More Tech news