I Inspected My Take-Home Interview Project. It Was a Whole Operation

I Inspected My Take-Home Interview Project. It Was a Whole Operation

A recruiter offered me an unusually high-paying Python role with a take-home assignment. Suspicious of the lack of vetting, I inspected the provided zip file and discovered malicious Git hooks designed to silently execute remote payloads. The attack chain installs Node.js dependencies like Hardhat and clipboard access tools, likely targeting crypto wallets. This sophisticated scam repurposes innocent open-source code to infect candidates' machines.

This is just a habit (may be from doing CTFs), whenever I get a random project folder, I just run tree -a to see what's lurking in the hidden directories.

More from this day

2026-07-22