Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. Sometimes the job interview just wants to gain code exec on your machine:

Sometimes the job interview just wants to gain code exec on your machine:

Geplant Angeheftet Gesperrt Verschoben Uncategorized
33 Beiträge 22 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • mushu@social.troll.academyM mushu@social.troll.academy

    Sometimes the job interview just wants to gain code exec on your machine:

    https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

    Local girl failed the coding interview:
    I don't think they've got a job for me anymore now that I got their repos deleted⁉️

    uint8_t@chaos.socialU This user is from outside of this forum
    uint8_t@chaos.socialU This user is from outside of this forum
    uint8_t@chaos.social
    schrieb zuletzt editiert von
    #24

    @mushu I wonder what the payload script contained

    mushu@social.troll.academyM 1 Antwort Letzte Antwort
    0
    • mushu@social.troll.academyM mushu@social.troll.academy

      Sometimes the job interview just wants to gain code exec on your machine:

      https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

      Local girl failed the coding interview:
      I don't think they've got a job for me anymore now that I got their repos deleted⁉️

      nycki@bark.lgbtN This user is from outside of this forum
      nycki@bark.lgbtN This user is from outside of this forum
      nycki@bark.lgbt
      schrieb zuletzt editiert von
      #25

      @mushu okay, why does she even HAVE that lever?

      1 Antwort Letzte Antwort
      0
      • mushu@social.troll.academyM mushu@social.troll.academy

        Sometimes the job interview just wants to gain code exec on your machine:

        https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

        Local girl failed the coding interview:
        I don't think they've got a job for me anymore now that I got their repos deleted⁉️

        un_bourguignon@piaille.frU This user is from outside of this forum
        un_bourguignon@piaille.frU This user is from outside of this forum
        un_bourguignon@piaille.fr
        schrieb zuletzt editiert von
        #26

        @mushu
        Let's say that their security is bad as f*ck... And, if they can't do any restore, their resilience is even badder.
        @R1Rail

        1 Antwort Letzte Antwort
        0
        • joshix@fosspri.deJ joshix@fosspri.de

          @mushu @morl99 I think IntelliJ also automatically executes stuff when you open a repo

          https://www.jetbrains.com/help/idea/project-security.html

          morl99@hessen.socialM This user is from outside of this forum
          morl99@hessen.socialM This user is from outside of this forum
          morl99@hessen.social
          schrieb zuletzt editiert von
          #27

          @joshix @mushu interesting, I have never felt the need for this: https://www.jetbrains.com/help/idea/settings-tools-startup-tasks.html

          Maybe something for other ecosystems...

          1 Antwort Letzte Antwort
          0
          • cppguy@infosec.spaceC cppguy@infosec.space

            @mushu

            Something I still don't understand (and didn't understand when I saw @0xabad1dea 's original post): why would crims target out-of-work developers, who are more tech-savvy than most people, probably don't have much money just now, and don't have access to company codebases?

            stepan@f.czS This user is from outside of this forum
            stepan@f.czS This user is from outside of this forum
            stepan@f.cz
            schrieb zuletzt editiert von
            #28

            @CppGuy maybe they hope the victims own some more popular repository or a package on something like npm so they can then infect developers who do have access to company stuff and have money. @mushu @0xabad1dea

            1 Antwort Letzte Antwort
            0
            • mushu@social.troll.academyM mushu@social.troll.academy

              Sometimes the job interview just wants to gain code exec on your machine:

              https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

              Local girl failed the coding interview:
              I don't think they've got a job for me anymore now that I got their repos deleted⁉️

              mushu@social.troll.academyM This user is from outside of this forum
              mushu@social.troll.academyM This user is from outside of this forum
              mushu@social.troll.academy
              schrieb zuletzt editiert von
              #29

              Thanks to @cxiao for highlighting these:

              https://www.jamf.com/blog/threat-actors-expand-abuse-of-visual-studio-code/
              https://opensourcemalware.com/blog/contagious-interview-vscode

              .. I do know that the version of tokenlinux.sh I retrieved also downloads node and executes something with it.

              cxiao@infosec.exchangeC 1 Antwort Letzte Antwort
              0
              • uint8_t@chaos.socialU uint8_t@chaos.social

                @mushu I wonder what the payload script contained

                mushu@social.troll.academyM This user is from outside of this forum
                mushu@social.troll.academyM This user is from outside of this forum
                mushu@social.troll.academy
                schrieb zuletzt editiert von
                #30

                @uint8_t might've been this: https://social.troll.academy/@mushu/115941118741449240

                1 Antwort Letzte Antwort
                0
                • mushu@social.troll.academyM mushu@social.troll.academy

                  Thanks to @cxiao for highlighting these:

                  https://www.jamf.com/blog/threat-actors-expand-abuse-of-visual-studio-code/
                  https://opensourcemalware.com/blog/contagious-interview-vscode

                  .. I do know that the version of tokenlinux.sh I retrieved also downloads node and executes something with it.

                  cxiao@infosec.exchangeC This user is from outside of this forum
                  cxiao@infosec.exchangeC This user is from outside of this forum
                  cxiao@infosec.exchange
                  schrieb zuletzt editiert von
                  #31

                  @mushu np, glad it didn't get you in this case and thanks for writing it up to warn others!

                  1 Antwort Letzte Antwort
                  0
                  • mushu@social.troll.academyM mushu@social.troll.academy

                    @zedaardv outch - sorry to hear that 🫤

                    I mean there are some cases where device surveillance makes sense from a compliance perspective, but it should never be a surprise and be clearly documented upfront.

                    zedaardv@mastodon.worldZ This user is from outside of this forum
                    zedaardv@mastodon.worldZ This user is from outside of this forum
                    zedaardv@mastodon.world
                    schrieb zuletzt editiert von
                    #32

                    @mushu Yeah, it was a weird place.

                    They wouldn't tell me what they wanted me to do, then got mad at me when I didn't do it.

                    Like I was supposed to be a mind reader.

                    1 Antwort Letzte Antwort
                    0
                    • mushu@social.troll.academyM mushu@social.troll.academy

                      Sometimes the job interview just wants to gain code exec on your machine:

                      https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                      Local girl failed the coding interview:
                      I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                      xinit@mastodon.coffeeX This user is from outside of this forum
                      xinit@mastodon.coffeeX This user is from outside of this forum
                      xinit@mastodon.coffee
                      schrieb zuletzt editiert von
                      #33

                      @mushu "To me this is the visual language of Blockchain/NFT scams mixed with the butthole motifs that AI companies like so much."

                      Beautifully written 😄

                      1 Antwort Letzte Antwort
                      0
                      • skorpy@chaos.socialS skorpy@chaos.social shared this topic
                      Antworten
                      • In einem neuen Thema antworten
                      Anmelden zum Antworten
                      • Älteste zuerst
                      • Neuste zuerst
                      • Meiste Stimmen



                      Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                      Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                      Impressum | Datenschutzerklärung | Nutzungsbedingungen

                      • Anmelden

                      • Du hast noch kein Konto? Registrieren

                      • Anmelden oder registrieren, um zu suchen
                      • Erster Beitrag
                        Letzter Beitrag
                      0
                      • Home
                      • Aktuell
                      • Tags
                      • Über dieses Forum