Live data from Hacker News

A backdoor in a LinkedIn job offer

roman.pt

151–160 of 331 posts

Re: A backdoor in a LinkedIn job offer

#151
post #16

> a recruiter at a small crypto startup [...] she described a broken proof-of-concept they needed a lead engineer for, and then sent me a public GitHub repo to review. Specifically, she asked me to “check out the deprecated Node modules issue.” > ...buried between walls of commented-out tests, the payload runs anything the server sends back to your machine. > npm runs prepare automatically after npm install, so just…

It’s been this bad for a little while, iirc have seen a few of these pop up over the last few years. And that’s just for the few someone’s caught/documented

Re: A backdoor in a LinkedIn job offer

#152
"Recruiters" are getting sophisticated.

I spoke on the phone with "Singapore based recruiters" a couple of times who wanted my services as a consultant for "advanced applications for semiconductor devices."

Turns out they were just fishing for inside information on my employer's end customer's applications.

Re: A backdoor in a LinkedIn job offer

#153

I'm working 3 remote jobs right now and I can tell you guys to really watch out. Often they are not malicious, just unsavory business practice where they want free consulting with no intention of hiring you. Another tell is the person is quick to jump to a take home screening project and they are quite good at getting at engineers heads that "leetcode is outdated/they dont believe in it" and whatever they want you to…

> Don't stay honest to those don't value it.

IMO you are either honest or you are not

Re: A backdoor in a LinkedIn job offer

#154
post #8

So, this is a crime right? Why isn't there a well known '911' for cybercrime to report things like this to and get help? Society needs to catch up with the actual dangers out there and build support networks for this ASAP. This is organized crime and needs organized defense to deal with it.

[deleted]

Re: A backdoor in a LinkedIn job offer

#155
post #18
post #8

So, this is a crime right? Why isn't there a well known '911' for cybercrime to report things like this to and get help? Society needs to catch up with the actual dangers out there and build support networks for this ASAP. This is organized crime and needs organized defense to deal with it.

https://www.ic3.gov You won't hear back from them, though. But, at least for US citizens (and possibly for anyone?), this is as far as I know the closest thing there is to an "Internet 911".

> You won't hear back from them

You might. (I have.) They were able to get a wire sent to a fraudster reversed. (Not my wire.)

Re: A backdoor in a LinkedIn job offer

#156

I really want to know what would've happened with an npm install, I guess something boring like crypto mining or identity theft?

You can actually test it yourself. The actual URL is in the post and the website is still up.

Seems like it actually loads a PNG image now, maybe the npm script adds some additional headers to trigger the payload.

Re: A backdoor in a LinkedIn job offer

#157
post #8

So, this is a crime right? Why isn't there a well known '911' for cybercrime to report things like this to and get help? Society needs to catch up with the actual dangers out there and build support networks for this ASAP. This is organized crime and needs organized defense to deal with it.

the main issue is that we lack a global '911'. secondary is the effort asymmetry between spinning up one of these scams (near 0 effort) and catching/prosecuting these scams (big effort, astronomical cost)

> main issue is that we lack a global '911'

406 MHz is pretty close [1]. If you have a radio that screams on that channel, chances are the nearest search-and-rescue operation will at least be notified.

[1] https://www.sarsat.noaa.gov/emergency-406-beacons/

Re: A backdoor in a LinkedIn job offer

#158
post #8

So, this is a crime right? Why isn't there a well known '911' for cybercrime to report things like this to and get help? Society needs to catch up with the actual dangers out there and build support networks for this ASAP. This is organized crime and needs organized defense to deal with it.

Unfortunately most evil cybercriminals know the "one weird trick" of "do your crimes in countries that don't care about the crimes"

Cut the cables

Re: A backdoor in a LinkedIn job offer

#159

Earlier quoted context omitted.

Unfortunately most evil cybercriminals know the "one weird trick" of "do your crimes in countries that don't care about the crimes"

I see several comments like this implying nothing can be done. But that is far from the truth. First, an agency that actually answered the phone could coordinate directly with LinkedIn and other tech companies to quickly take down these fake accounts and minimize harm to others. We all know how incredibly hard it is to contact a tech company. Second, an agency that answers the phone could help less technical people f…

Won't that just create another channel for social engineering to delete a victim's account?

Re: A backdoor in a LinkedIn job offer

#160

Earlier quoted context omitted.

The scammers are in a different whole uncooperative country.

Or they may be in this country, but uses proxies, virtual machines, hostings from uncooperative country.

Less likely and when they are usually they're immigrants and if they're investigated they just go back home.
Post reply on HN