ended5월 15일· 1 sources

The Interview Trap: How Job Assignments Became Malware Vectors

개발자를 노린 가짜 면접 과제: 정보 탈취 악성코드의 정체

Why it matters

This attack reveals a critical vulnerability in developer recruitment workflows, exploiting legitimate-looking job interview assignments to deliver sophisticated credential stealers targeting API keys, credentials, and crypto assets. The malware leverages npm's automatic postinstall hooks to execute before developers can audit code, turning the hiring process into a supply chain attack vector. The attack's precision—from professional social engineering to keyword-targeted file system searches—demonstrates why developers must audit all code before execution, regardless of source credibility.

1
Sources
+0
24h
Growth
4d
Active
Infostealernpm postinstallCredential exfiltrationJob interviewJavaScript obfuscation

Sources

Related Issues