ended5월 15일· 1 sources
The Interview Trap: How Job Assignments Became Malware Vectors
개발자를 노린 가짜 면접 과제: 정보 탈취 악성코드의 정체
Why it matters
This attack reveals a critical vulnerability in developer recruitment workflows, exploiting legitimate-looking job interview assignments to deliver sophisticated credential stealers targeting API keys, credentials, and crypto assets. The malware leverages npm's automatic postinstall hooks to execute before developers can audit code, turning the hiring process into a supply chain attack vector. The attack's precision—from professional social engineering to keyword-targeted file system searches—demonstrates why developers must audit all code before execution, regardless of source credibility.
1
Sources
+0
24h
—
Growth
4d
Active
Infostealernpm postinstallCredential exfiltrationJob interviewJavaScript obfuscation