Having Fun With a Scamming Crypto Job

2025-04-09 Thanh

https://nguyenhuythanh.com/posts/having-fun-with-a-scamming-crypto-job/

Thumbnail for Having Fun With a Scamming Crypto Job

A developer analyzed a crypto job scam in which an impersonated recruiter pushed a technical assessment that required downloading and running a code repository. Review of the dependencies found a suspicious Go package, github.com/TedCollin/uniroute/v2, containing base64-encoded infrastructure that resolved to a download URL on download.datatabletemplate.xyz. The package included platform-specific code designed to fetch a binary into a temporary path and execute it with OS-specific behavior, including a Linux path that ran the downloaded file through nohup and bash. The source does not attribute the activity to a named actor, but it provides a practical example of recruiter impersonation and malicious dependency abuse in cryptocurrency-themed job lures.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN datatabletemplate.xyz 2025-04-09 2025-10-28
URL https://download.datatabletempl… 2025-04-09 2025-10-28
DOMAIN download.datatabletemplate.xyz 2025-04-09 2025-10-28
URL https://tildes.net/~comp/1n9o/h… 2025-04-09 2025-04-09

Related Reports

« Back