Personal experience regarding an interview that ended in a scam
2024-12-03 • sohay666 •
https://sohay666.github.io/article/en/reversing-scam-interview-base-on-js-project.html
A fake remote job interview led the victim to clone and run a Node.js project containing obfuscated malicious JavaScript. The code collected host details and targeted sensitive data from Solana wallet configuration, Exodus, browser credential stores, Chrome and Brave profiles, macOS Keychain, and application configuration files. Dynamic analysis showed staged downloads from 86.104.74.51:1224, including a backdoor/dropper, a browser-focused malware component whose payload URL was XOR-obfuscated with the key !!!HappyPenguin1950!!!, and a keylogger component. The keylogger watched for browser processes, checked for crypto-wallet mnemonic material, and posted captured data to 95.164.7.171:8637/api/clip, making the case useful for tracking interview-themed developer targeting and credential-theft tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 86.104.74.51 | 2024-12-03 | 2025-11-13 |
| IPv4 | 95.164.7.171 | 2024-10-14 | 2025-07-26 |
| IPv4 | 23.254.229.101 | 2024-12-03 | 2025-04-25 |
| URL | https://pastebin.com/raw/suEqUQ… | 2024-12-03 | 2024-12-03 |