Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. Sometimes the job interview just wants to gain code exec on your machine:

Sometimes the job interview just wants to gain code exec on your machine:

Geplant Angeheftet Gesperrt Verschoben Uncategorized
33 Beiträge 22 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • mushu@social.troll.academyM mushu@social.troll.academy

    Sometimes the job interview just wants to gain code exec on your machine:

    https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

    Local girl failed the coding interview:
    I don't think they've got a job for me anymore now that I got their repos deleted⁉️

    fischkind@chaos.socialF This user is from outside of this forum
    fischkind@chaos.socialF This user is from outside of this forum
    fischkind@chaos.social
    schrieb zuletzt editiert von
    #15

    @mushu Maybe the real coding challenge was getting their repos deleted and now they'll offer you a job as their head of cyber security? 🤔

    1 Antwort Letzte Antwort
    0
    • mushu@social.troll.academyM mushu@social.troll.academy

      Sometimes the job interview just wants to gain code exec on your machine:

      https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

      Local girl failed the coding interview:
      I don't think they've got a job for me anymore now that I got their repos deleted⁉️

      freya@raru.reF This user is from outside of this forum
      freya@raru.reF This user is from outside of this forum
      freya@raru.re
      schrieb zuletzt editiert von
      #16

      @mushu I hope you find less adversarial prospective employers!

      mushu@social.troll.academyM 1 Antwort Letzte Antwort
      0
      • mushu@social.troll.academyM mushu@social.troll.academy

        Sometimes the job interview just wants to gain code exec on your machine:

        https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

        Local girl failed the coding interview:
        I don't think they've got a job for me anymore now that I got their repos deleted⁉️

        cppguy@infosec.spaceC This user is from outside of this forum
        cppguy@infosec.spaceC This user is from outside of this forum
        cppguy@infosec.space
        schrieb zuletzt editiert von
        #17

        @mushu

        Something I still don't understand (and didn't understand when I saw @0xabad1dea 's original post): why would crims target out-of-work developers, who are more tech-savvy than most people, probably don't have much money just now, and don't have access to company codebases?

        0xabad1dea@infosec.exchange0 stepan@f.czS 2 Antworten Letzte Antwort
        0
        • cppguy@infosec.spaceC cppguy@infosec.space

          @mushu

          Something I still don't understand (and didn't understand when I saw @0xabad1dea 's original post): why would crims target out-of-work developers, who are more tech-savvy than most people, probably don't have much money just now, and don't have access to company codebases?

          0xabad1dea@infosec.exchange0 This user is from outside of this forum
          0xabad1dea@infosec.exchange0 This user is from outside of this forum
          0xabad1dea@infosec.exchange
          schrieb zuletzt editiert von
          #18

          @CppGuy @mushu most people applying to non-entry-level programming jobs are not out of work, the industry is notorious for requiring job hopping every two years as the only way to get a raise...

          additionally, many of these fake job openings are specifically in cryptocoins/gambling/etc and people applying to them are more likely to have random wallet keys lying around.

          1 Antwort Letzte Antwort
          0
          • freya@raru.reF freya@raru.re

            @mushu I hope you find less adversarial prospective employers!

            mushu@social.troll.academyM This user is from outside of this forum
            mushu@social.troll.academyM This user is from outside of this forum
            mushu@social.troll.academy
            schrieb zuletzt editiert von
            #19

            @freya thanks 💖
            If fedi is any measure there are amazing, kind people out there. Some of them even do software.

            1 Antwort Letzte Antwort
            0
            • mushu@social.troll.academyM mushu@social.troll.academy

              Sometimes the job interview just wants to gain code exec on your machine:

              https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

              Local girl failed the coding interview:
              I don't think they've got a job for me anymore now that I got their repos deleted⁉️

              agitatra@berlin.socialA This user is from outside of this forum
              agitatra@berlin.socialA This user is from outside of this forum
              agitatra@berlin.social
              schrieb zuletzt editiert von
              #20

              @mushu Did I got it wrong or was this a: "No Backup, No Mercy"-situation? I mean who gives more than strictly limited write access to strangers?
              BTW: I got my first it-job as a tester by crashing their system during the interview.

              1 Antwort Letzte Antwort
              0
              • mushu@social.troll.academyM mushu@social.troll.academy

                Sometimes the job interview just wants to gain code exec on your machine:

                https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                Local girl failed the coding interview:
                I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                ben@mastodon.lubar.meB This user is from outside of this forum
                ben@mastodon.lubar.meB This user is from outside of this forum
                ben@mastodon.lubar.me
                schrieb zuletzt editiert von
                #21

                @mushu I wonder if anyone has made something that intentionally looks interesting to corporations that might be looking to steal code and ignore its license and added a .vscode/tasks.json that plays a really loud fart sound when executed

                1 Antwort Letzte Antwort
                0
                • mushu@social.troll.academyM mushu@social.troll.academy

                  Sometimes the job interview just wants to gain code exec on your machine:

                  https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                  Local girl failed the coding interview:
                  I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                  zedaardv@mastodon.worldZ This user is from outside of this forum
                  zedaardv@mastodon.worldZ This user is from outside of this forum
                  zedaardv@mastodon.world
                  schrieb zuletzt editiert von
                  #22

                  @mushu
                  Wow, reading these comments made me remember this job I had briefly (over 15 years ago) in Stockholm.

                  I had a mac laptop, my work laptop was also a mac. And I was working with Postgres.

                  I had the job for about 2 weeks before they let me go.

                  I noticed at some point that they had installed a root-kit on my computer.
                  (the were a sports betting company)

                  mushu@social.troll.academyM 1 Antwort Letzte Antwort
                  0
                  • zedaardv@mastodon.worldZ zedaardv@mastodon.world

                    @mushu
                    Wow, reading these comments made me remember this job I had briefly (over 15 years ago) in Stockholm.

                    I had a mac laptop, my work laptop was also a mac. And I was working with Postgres.

                    I had the job for about 2 weeks before they let me go.

                    I noticed at some point that they had installed a root-kit on my computer.
                    (the were a sports betting company)

                    mushu@social.troll.academyM This user is from outside of this forum
                    mushu@social.troll.academyM This user is from outside of this forum
                    mushu@social.troll.academy
                    schrieb zuletzt editiert von
                    #23

                    @zedaardv outch - sorry to hear that 🫤

                    I mean there are some cases where device surveillance makes sense from a compliance perspective, but it should never be a surprise and be clearly documented upfront.

                    zedaardv@mastodon.worldZ 1 Antwort Letzte Antwort
                    0
                    • mushu@social.troll.academyM mushu@social.troll.academy

                      Sometimes the job interview just wants to gain code exec on your machine:

                      https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                      Local girl failed the coding interview:
                      I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                      uint8_t@chaos.socialU This user is from outside of this forum
                      uint8_t@chaos.socialU This user is from outside of this forum
                      uint8_t@chaos.social
                      schrieb zuletzt editiert von
                      #24

                      @mushu I wonder what the payload script contained

                      mushu@social.troll.academyM 1 Antwort Letzte Antwort
                      0
                      • mushu@social.troll.academyM mushu@social.troll.academy

                        Sometimes the job interview just wants to gain code exec on your machine:

                        https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                        Local girl failed the coding interview:
                        I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                        nycki@bark.lgbtN This user is from outside of this forum
                        nycki@bark.lgbtN This user is from outside of this forum
                        nycki@bark.lgbt
                        schrieb zuletzt editiert von
                        #25

                        @mushu okay, why does she even HAVE that lever?

                        1 Antwort Letzte Antwort
                        0
                        • mushu@social.troll.academyM mushu@social.troll.academy

                          Sometimes the job interview just wants to gain code exec on your machine:

                          https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                          Local girl failed the coding interview:
                          I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                          un_bourguignon@piaille.frU This user is from outside of this forum
                          un_bourguignon@piaille.frU This user is from outside of this forum
                          un_bourguignon@piaille.fr
                          schrieb zuletzt editiert von
                          #26

                          @mushu
                          Let's say that their security is bad as f*ck... And, if they can't do any restore, their resilience is even badder.
                          @R1Rail

                          1 Antwort Letzte Antwort
                          0
                          • joshix@fosspri.deJ joshix@fosspri.de

                            @mushu @morl99 I think IntelliJ also automatically executes stuff when you open a repo

                            https://www.jetbrains.com/help/idea/project-security.html

                            morl99@hessen.socialM This user is from outside of this forum
                            morl99@hessen.socialM This user is from outside of this forum
                            morl99@hessen.social
                            schrieb zuletzt editiert von
                            #27

                            @joshix @mushu interesting, I have never felt the need for this: https://www.jetbrains.com/help/idea/settings-tools-startup-tasks.html

                            Maybe something for other ecosystems...

                            1 Antwort Letzte Antwort
                            0
                            • cppguy@infosec.spaceC cppguy@infosec.space

                              @mushu

                              Something I still don't understand (and didn't understand when I saw @0xabad1dea 's original post): why would crims target out-of-work developers, who are more tech-savvy than most people, probably don't have much money just now, and don't have access to company codebases?

                              stepan@f.czS This user is from outside of this forum
                              stepan@f.czS This user is from outside of this forum
                              stepan@f.cz
                              schrieb zuletzt editiert von
                              #28

                              @CppGuy maybe they hope the victims own some more popular repository or a package on something like npm so they can then infect developers who do have access to company stuff and have money. @mushu @0xabad1dea

                              1 Antwort Letzte Antwort
                              0
                              • mushu@social.troll.academyM mushu@social.troll.academy

                                Sometimes the job interview just wants to gain code exec on your machine:

                                https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                                Local girl failed the coding interview:
                                I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                                mushu@social.troll.academyM This user is from outside of this forum
                                mushu@social.troll.academyM This user is from outside of this forum
                                mushu@social.troll.academy
                                schrieb zuletzt editiert von
                                #29

                                Thanks to @cxiao for highlighting these:

                                https://www.jamf.com/blog/threat-actors-expand-abuse-of-visual-studio-code/
                                https://opensourcemalware.com/blog/contagious-interview-vscode

                                .. I do know that the version of tokenlinux.sh I retrieved also downloads node and executes something with it.

                                cxiao@infosec.exchangeC 1 Antwort Letzte Antwort
                                0
                                • uint8_t@chaos.socialU uint8_t@chaos.social

                                  @mushu I wonder what the payload script contained

                                  mushu@social.troll.academyM This user is from outside of this forum
                                  mushu@social.troll.academyM This user is from outside of this forum
                                  mushu@social.troll.academy
                                  schrieb zuletzt editiert von
                                  #30

                                  @uint8_t might've been this: https://social.troll.academy/@mushu/115941118741449240

                                  1 Antwort Letzte Antwort
                                  0
                                  • mushu@social.troll.academyM mushu@social.troll.academy

                                    Thanks to @cxiao for highlighting these:

                                    https://www.jamf.com/blog/threat-actors-expand-abuse-of-visual-studio-code/
                                    https://opensourcemalware.com/blog/contagious-interview-vscode

                                    .. I do know that the version of tokenlinux.sh I retrieved also downloads node and executes something with it.

                                    cxiao@infosec.exchangeC This user is from outside of this forum
                                    cxiao@infosec.exchangeC This user is from outside of this forum
                                    cxiao@infosec.exchange
                                    schrieb zuletzt editiert von
                                    #31

                                    @mushu np, glad it didn't get you in this case and thanks for writing it up to warn others!

                                    1 Antwort Letzte Antwort
                                    0
                                    • mushu@social.troll.academyM mushu@social.troll.academy

                                      @zedaardv outch - sorry to hear that 🫤

                                      I mean there are some cases where device surveillance makes sense from a compliance perspective, but it should never be a surprise and be clearly documented upfront.

                                      zedaardv@mastodon.worldZ This user is from outside of this forum
                                      zedaardv@mastodon.worldZ This user is from outside of this forum
                                      zedaardv@mastodon.world
                                      schrieb zuletzt editiert von
                                      #32

                                      @mushu Yeah, it was a weird place.

                                      They wouldn't tell me what they wanted me to do, then got mad at me when I didn't do it.

                                      Like I was supposed to be a mind reader.

                                      1 Antwort Letzte Antwort
                                      0
                                      • mushu@social.troll.academyM mushu@social.troll.academy

                                        Sometimes the job interview just wants to gain code exec on your machine:

                                        https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                                        Local girl failed the coding interview:
                                        I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                                        xinit@mastodon.coffeeX This user is from outside of this forum
                                        xinit@mastodon.coffeeX This user is from outside of this forum
                                        xinit@mastodon.coffee
                                        schrieb zuletzt editiert von
                                        #33

                                        @mushu "To me this is the visual language of Blockchain/NFT scams mixed with the butthole motifs that AI companies like so much."

                                        Beautifully written 😄

                                        1 Antwort Letzte Antwort
                                        0
                                        • skorpy@chaos.socialS skorpy@chaos.social shared this topic
                                        Antworten
                                        • In einem neuen Thema antworten
                                        Anmelden zum Antworten
                                        • Älteste zuerst
                                        • Neuste zuerst
                                        • Meiste Stimmen



                                        Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                                        Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                                        Impressum | Datenschutzerklärung | Nutzungsbedingungen

                                        • Anmelden

                                        • Du hast noch kein Konto? Registrieren

                                        • Anmelden oder registrieren, um zu suchen
                                        • Erster Beitrag
                                          Letzter Beitrag
                                        0
                                        • Home
                                        • Aktuell
                                        • Tags
                                        • Über dieses Forum