ended6월 16일· 1 sources
The LinkedIn Supply Chain Trap: Stolen Identities and Hidden npm Backdoors
GitHub 백도어를 노린 LinkedIn 채용 사기: 도용된 신원의 공급망 공격
Why it matters
This article reveals a coordinated supply chain attack using stolen LinkedIn and GitHub identities to distribute npm backdoors disguised as code review requests. By exploiting the npm prepare script's automatic execution during install, attackers bypassed developer skepticism and triggered malicious payloads at a critical moment in the development workflow. The incident underscores the growing risk of social engineering combined with technical deception in open-source pipelines and highlights the need for better verification mechanisms in recruitment processes.
1
Sources
+0
24h
—
Growth
4d
Active
GitHub backdoornpm exploitsocial engineeringLinkedIn scamidentity theft