I just got a scam attempt by a Linkedin "recruiter"

2025-03-14 Bruno

https://archive.md/yJ5iY

Thumbnail for I just got a scam attempt by a Linkedin "recruiter"

A LinkedIn recruiter-themed lure pushed a developer toward a Bitbucket repository and pressured them to run the project quickly, matching fake-job social engineering used to compromise software developers. The repository’s visible Node.js code appeared ordinary, but a hidden horizontally displaced payload in socket.js executed when the victim ran npm start. The payload collected host and environment details, contacted a remote server, wrote additional payloads into the user’s home directory, executed them through Node child_process.exec, and repeated callback activity on a timer. The account and repository indicators, including an old single-commit project and immediate code-delivery pressure, provide practical red flags for detecting recruiter-lure intrusions before code execution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fe64da1fe1f75b8030875b67434fff5b 2025-03-14 2025-03-14

Related Actors

Related Reports

« Back