Having Fun With a Scamming Crypto Job
2025-04-09 • Thanh •
https://nguyenhuythanh.com/posts/having-fun-with-a-scamming-crypto-job/
A developer analyzed a crypto job scam in which an impersonated recruiter pushed a technical assessment that required downloading and running a code repository. Review of the dependencies found a suspicious Go package, github.com/TedCollin/uniroute/v2, containing base64-encoded infrastructure that resolved to a download URL on download.datatabletemplate.xyz. The package included platform-specific code designed to fetch a binary into a temporary path and execute it with OS-specific behavior, including a Linux path that ran the downloaded file through nohup and bash. The source does not attribute the activity to a named actor, but it provides a practical example of recruiter impersonation and malicious dependency abuse in cryptocurrency-themed job lures.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | datatabletemplate.xyz | 2025-04-09 | 2025-10-28 |
| URL | https://download.datatabletempl… | 2025-04-09 | 2025-10-28 |
| DOMAIN | download.datatabletemplate.xyz | 2025-04-09 | 2025-10-28 |
| URL | https://tildes.net/~comp/1n9o/h… | 2025-04-09 | 2025-04-09 |