Posted by codedge 5 hours ago
Do not install anything on your machine, ever. Tell them politely ~to fuck off~ that you are not interested and move on. I know the desperation to be jobless will obfuscate your mind but again, never ever install anything on your machine when job hunting. I've seen people lose their crypto savings in seconds to say the least.
You've been warned.
What? There is no world outside github?
The rest of the article is legit, but they had to insert some monopoly worship...
Bad actor had prepared the set up so precisely that Claude Code could not detect it.
Malware Bytes? Acronis? There must be some template…
Maybe I work in a different field but last year when I was still looking for jobs, only one company asked for coding assignment and every other company did coding interview which is always browser based editor.
I feel like the industry is mature enough that you can tell a company that sends you a zip file of code to f-off.
Because both the company and you know it’s the most effective job interview “filter” in SWE roles.
> on your own time
It may not be unpaid if you’re applying to a decent company.
The issue here is their poor implementation (zip file), not the concept itself, IMO.
https://opensourcemalware.com/blog/latest-contagious-intervi...
> A note on the AI part: Claude Code was not able to detect any strange things when just prompted to scan the code base for unusual patterns.
> read process.env directly, which in this app means MONGO_URI, JWT_SECRET, SENDGRID_API_KEY, CLOUDINARY_API_SECRET, PAYTM_MERCHANT_KEY
yeah it can run arbitrary malicious code, but let’s also highlight that it can read the fake app’s own dummy environment variables
> When the victim connects out to […], the server sees the source address on the accepted socket, exactly as any web server sees a visitor’s IP. No discovery, no scanning, no registration of an address. This is precisely why outbound-only design is so convenient for the attacker: it works behind NAT, CGNAT, a corporate proxy, or a home router with zero configuration, and it doesn’t matter if the victim’s IP changes.
huge
> If there is no UI/Desktop environment the module for leaking browser data or screenshots is self-limiting.
yeah this is why a VM is important, it’s because it doesn’t have a UI so screenshots don’t work
> … and reinstall your OS - better safe than sorry.
yeah just for thoroughness’s sake after having a RAT installed (hopefully you didn’t do this step last)