Dev targeted by sophisticated job scam: 'I let my guard down, and ran the freaking code'
ID: a477f67e-ada7-5e7d-a507-3afd56b70c09
STIX ID: report--a477f67e-ada7-5e7d-a507-3afd56b70c09
Feed Name: The Register (Security)
A developer responded to a fake remote job interview and ran a provided coding-test repository which deployed a hidden macOS shell script that downloaded a Go backdoor. In about 56 seconds the attackers exfiltrated 634 saved Chrome passwords, the macOS keychain, and MetaMask wallet data; the malware includes capabilities for shell execution, file theft, credential extraction and persistence, and uses a custom RC4-encrypted protocol. The campaign was delivered via social-engineering (fake company profile, staged interviews) and a dependency-of-dependency supply chain tactic; investigators and the victim note similarities to previous incidents attributed to North Korean–linked actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
