Live data from Hacker News

A backdoor in a LinkedIn job offer

roman.pt

241–250 of 331 posts

Re: A backdoor in a LinkedIn job offer

#241
post #191

The difference between pre- and post-chatbot writeups is stark: https://igor-blue.github.io/2021/03/24/apt1.html $100 says OP is Claude

I don't want to be cynical, but maybe spending hours every day using Claude has made some of us particularly attuned to picking this up. For some reason as soon as I read "The trap was in app/test/index.js," I instantly knew it was Claude. It's too bad, because there will obviously be some false positives, but it makes me immediately disregard the author.

I sometimes use the Claude app with text to speech enabled. It’s got a quite distinctive voice/tempo combo when it’s outputting speech.

Whenever I see a typical Claude-tell in writing, my internal reading voice switches automatically from my internal monologue’s voice into Claude’s voice for the rest of the piece.

Re: A backdoor in a LinkedIn job offer

#242
post #16

> a recruiter at a small crypto startup [...] she described a broken proof-of-concept they needed a lead engineer for, and then sent me a public GitHub repo to review. Specifically, she asked me to “check out the deprecated Node modules issue.” > ...buried between walls of commented-out tests, the payload runs anything the server sends back to your machine. > npm runs prepare automatically after npm install, so just…

I've been freelancing for over a decade. This stuff is every third crypto related job. They're all malware repos running scripts the moment you turn on vscode hoovering up everything they can on your computer.

It's the least surprising thing once you've put yourself out there, very strange watching people here think it's novel, I expect it by default at this point, a stranger handing you code needs to go into a vm, would you let them hand you some candy with a wink too?

Re: A backdoor in a LinkedIn job offer

#244

Earlier quoted context omitted.

Unfortunately most evil cybercriminals know the "one weird trick" of "do your crimes in countries that don't care about the crimes"

I see several comments like this implying nothing can be done. But that is far from the truth. First, an agency that actually answered the phone could coordinate directly with LinkedIn and other tech companies to quickly take down these fake accounts and minimize harm to others. We all know how incredibly hard it is to contact a tech company. Second, an agency that answers the phone could help less technical people f…

> But that is far from the truth

Just install a Russian locale on your computer to prevent malicious programs even starting and get on with your day because it's the truth.

Snowden is a free man in 2026 despite the United States of America very much wanting to put him in jail.

Re: A backdoor in a LinkedIn job offer

#245
post #122

> I reported the repo to GitHub and the recruiter to LinkedIn. So far nothing has changed and the code is still up. Oh, Microsoft.

Weird, isn't it? Microsoft owns all of LinkedIn, Github and NPM. All three either have security or stability issues, which seems to get worse, not better, as microsoft goes more into AI. Where is the AI productivity (10x by some accounts!) within the company going to?

Keep in mind this is the company that makes Windows, a product so insecure they lost a lawsuit over it

Re: A backdoor in a LinkedIn job offer

#246
post #240
post #208

Earlier quoted context omitted.

Something I've always wondered, because I'm a bit of a contrarian and I wonder if we're really any different: Could an American citizen hack and steal from Iranians and Russians with impunity from America? The issues that prevent the US from extraditing Russians who hack us -- don't they work both ways?

Legally speaking, no - it would still be a criminal offence. Practically speaking, there is zero chance that the USA would extradite someone to Iran, even if they weren't currently at war with them. Whether they did anything about it would probably depend on exactly what the situation was - there's a big of difference between targeted IRGC or defence systems and ransomwaring an Iranian hospital or scamming random cit…

What would happen if you honestly listed your earnings on your tax forms?

Re: A backdoor in a LinkedIn job offer

#248
post #21

I've been getting some job offers on LinkedIn, all of them are shady af. Apply using a platform. Apply recording a video of yourself. Apply by resolving a calibration code test (behind a code platform)...

My favorite was a job posting through a company called ladders

Saw it in the soup of other job posting, went to apply, it took me to some other job portal, ok whatever, this is normal, filled out all the forms as one does, and then reached the end and the site told me they'd submitted my application, and here were some other jobs I could apply to with the same application. Useful, right?

Click any of them, or anywhere else on the page, and a full screen modal takeover comes up, demanding you pay $50/application.

I closed the tab, but watched the email they sent me from the first job app. It went nowhere. Eventually applied to the company directly, on their job portal, and when I got to a real recruiter later, they said they never received my first app. My guess is ladders never even sent it and wouldn't until I paid up

Best part was ladders continued to spam my email inbox with job application invitations, each one wanting the same $50, until I blocked the fastmail throw away

I also had a "recruiter" reach out to me about a "role I'd be a good fit in". Made the meeting, and immediately some red flags. Audio and video were about 2 seconds out of sync. Guy then proceeded to try and pitch me on a similar job board, with the same $50/application cost, only this one had a 10 weeks salary cost on placement as well

I told him I wasn't interested.

Maybe these are just more traditional scams or whatever, not the malware type the op is about, but they still piss me off

Re: A backdoor in a LinkedIn job offer

#250
post #56

Earlier quoted context omitted.

LinkedIn offers no way for $company to disavow users who claim to work for $company - they will appear on the official company page as long as it's in their profile. We've had fake recruiters that claim to work for us running basically the same scam. These are great fake profiles: LinkedIn Premium, tons of relevant posts, etc... but they don't work for us, and we get angry messages from people saying our recruiter tr…

My last 2 companies, LinkedIn asked me to add an email address associated with the said company and actually confirm via said email in order to add them to my profile. So, if I worked for FooCompany, I had to have a @FooCompany.com email which is setup by someone at the company itself. Does this not cover what you're talking about?

I had a LinkedIn account connected to my company email and one day I found myself locked out.

They want me to upload a govt id and blink my eyes in a video to get unlocked.

They can go jump.

Post reply on HN