wxw 21 minutes ago

> They embedded a script that checks the victim’s host operating system and silently executes a remote payload.

Seems like this is becoming a recurring theme, similar story was on the front page last month.

https://news.ycombinator.com/item?id=48546294

  • guessmyname 15 minutes ago

    > […] and silently executes a remote payload

    Silently only because @OP is not running Little Snitch (or the equivalent on Windows/Linux).

    I’m in the habit of running `tree -a` or the more modern `erd --hidden` but in this case I wouldn’t have needed to, and I wouldn’t have had to audit the scripts either. Little Snitch would have popped up an alert the moment cURL tried to reach that remote server, which is obviously suspicious, and I would have ended the “interview” right there.

nphardon 27 minutes ago

always a good day when we get an a post on front actually related to hacking on hackernews.

darth_avocado 6 minutes ago

If LinkedIn actually cared about preventing scams, they could implement verification using company emails if you want to list your current employment. And if it is too much of a heavy burden, then at the minimum you should have it as an optional feature that recruiters would have to comply with, if they want to be legitimate.

ge96 37 minutes ago

There was a funny video I saw recently someone's running Red Star OS on their computer and a scammer is trying to scam them thinking it's Windows

Unrelated to this git pre commit hook attack but yeah

ChrisMarshallNY 45 minutes ago

I assume these types of things are going to become more and more common.

Looks like these folks really did their homework.

It's nasty, but I have to respect their skills. I'll bet it works, quite often.

  • LoganDark 39 minutes ago

    Their "skills" might just be borrowed from some LLM.

    • throw_m239339 35 minutes ago

      Yeah, this scam is probably all automated at first place. Welcome to the "agent era"...

    • ChrisMarshallNY 16 minutes ago

      I dunno. The Norks seem to be really good at this, and have been, for a long time.

      I suspect it's clever, experienced, engineers, leveraging LLMs.

  • CITIZENDOT 34 minutes ago

    yea, i had fun looking around, this felt like a ctf challenge lol. if they had any vuln on their server, it would've been even better.

gtowey 37 minutes ago

My takeaway from this is that I should use the same defense as when someone calls you "from you bank". When they reach out directly, go to the real company's site to apply and contact a real recruiter. If you can't validate that the business is legit before, then assume malfeasance.

  • technion 29 minutes ago

    Companies make this hard, a bit like various email scams where legit company communication comes from seemingly random domains (hello paypal). Often the company is legit, but theres no public contact that knows anything about the recruiter thats working for them.

    • bombcar 26 minutes ago

      Healthcare companies are the WORST at this - they will send you legitimate email from h34lthc4re.biz with a heart-happy-health.phishing.info link that you HAVE to use - and it's all legit.

  • paxys 24 minutes ago

    Even if the attempt is legit, going to the company’s website/careers page to try and reach them is pointless. You application will just get lost among the thousands of others. Your best bet is to ask the recruiter to email you and check for a @<company.com> email address. And even if the attempt checks out don’t run untrusted code on your machine.

  • yieldcrv 17 minutes ago

    it was in this moment, that gtowey’s outdated job solutions transitioned them from unc to boomer

rdksu 33 minutes ago

Bruh the harry potter theme song scared the shit out of me as it turned itself on. Bad UX for a personal site. Great article btw !

  • CITIZENDOT 27 minutes ago

    sorry, i added it to set the mood for my site :') yk, like moving lamps at the top, hanging dementor at the right side (only visible on desktops).

    should i remove it?

    • john_strinlai 16 minutes ago

      >should i remove it?

      there is no place for fun, whimsy, moods, or personalization on the web. sorry.

      (no, at least not at the request of random internet stranger #10545346)

    • Lammy 15 minutes ago

      Middle ground: make it respect `prefers-reduced-motion` :)

    • seanobannon 12 minutes ago

      absolutely not! it is a delightful source of whimsy on an increasingly uniform web

    • projektfu 4 minutes ago

      No, it's your playground. My podcast was talking about the music the guest was making and I thought he was playing something Potter related.

  • ladybro 19 minutes ago

    Where can one be whimsical and fun if not for a personal site?