| |
A fake job interview scheme on LinkedIn uses a seemingly legitimate coding challenge to compromise candidates' systems. The malicious code, disguised within a TypeScript project, downloads and executes remote code that can steal sensitive credentials, environment variables, and system information by leveraging Node.js functions like child_process and fs. Red flags include non-company email addresses, lack of initial screening calls, and suspicious code that connects to external endpoints.
Read Full Article →
← More Tech news