frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Are they trying to hack me?

3•dgrcode•2h ago
I'm in the middle of an interaction that has raised a few red flags, and at this point I'm confident this is part of hacking attempt. But I thought asking here could give me a better perspective from an outsider. Here is the sequence of events:

Someone reaches out in Linkedin claiming to have full time and part time roles that match my profile. I say I could be interested in part time work and they immediately reply that there's a 4k monthly salary offer for 15-20 hours per week.

I reply that's half my hourly rate and they reply the client is almost willing to accept but wants to meet with me first. 1st red flag: no problem with doubling the offer

I accept and book a time with their technical person. 2nd red flag: the calendar had pretty much full availability

They tell me to complete a task before the meeting and provide a Microsoft Teams chat with someone from their team to talk about the task.

The person in the chat sends me screenshot of two issues. I ask if they have the code in github, to which they replied "github?". 3rd red flag

Then the same parson sends me a zip file and ask about my node version. 4th red flag

At this point I'm already suspicious and not willing to run that code on my machine. I get a fresh linux install on an old machine and download the code. I asked Cursor to find anything suspicious, and the only thing was a dependency mismatch between package.json and package-lock.json. I check the package present in package-lock, `json-map-source`, which is marked as a malicious package on https://security.snyk.io/package/npm/json-map-source. This package was removed from npm 18 days ago. Big red flag.

I check what's npm's resolution of that mismatch, and I find it would install `json-mappings`. I check on npm this package was created 18 days ago, and the first and only version is 2.3.8, which happens to be the same version flagged as malicious for the package `json-map-source`. Massive red flag

Furthermore, the package is not on git, it's uploaded by a throwaway email, and the README that is shown in npm list the yarn install command as `yarn add json-map-source` (the malicious package). In the code the package is just loaded and passed as middleware to an express app. The package has `sqlite3` as native dependency, which compiles native code.

As I'm writing this message I really don't see how this could be something other than a hack attempt, but I'd love to have someone else's input on this. Especially from people more knowledgeable about security than me, which is easy.

Thanks!

Comments

uyzstvqs•1h ago
Yes, found the malware in json-mappings. /lib/const.js contains DEV_API_KEY, which is a base64 encoded URL to the actual malware, hosted on an external service. This variable gets used by /lib/caller.js to download and run it. The rest of the project is just copied from pinojs/pino.

Greta Thunberg has been arrested for terrorism in London for holding a sign

https://old.reddit.com/r/LateStageCapitalism/comments/1ptwgxi/greta_thunberg_has_been_arrested_on...
2•testing22321•1m ago•0 comments

Imagebyqwen.com – Fast AI text-to-photo using Qwen

https://imagebyqwen.com
1•mariolattik•1m ago•1 comments

Court Rejects Attempts to Manufacture Common Law Notice-and-Takedown Duties

https://blog.ericgoldman.org/archives/2025/12/district-court-again-rejects-plaintiffs-attempts-to...
1•hn_acker•4m ago•1 comments

Automat

https://en.wikipedia.org/wiki/Automat
1•helterskelter•4m ago•0 comments

Weighted Selection Process for H1B registrations[pdf]

https://public-inspection.federalregister.gov/2025-23853.pdf
1•anonygoat•5m ago•1 comments

I foretold that Mac app notarization is security theater

https://lapcatsoftware.com/articles/2025/12/5.html
3•lladnar•5m ago•0 comments

What Is WebRTC? Definition, Use Cases, How It Works

https://www.red5.net/blog/what-is-webrtc/
1•mondainx•6m ago•0 comments

Why Coca-Cola Never Changed Its Red

https://picxstudio.com
1•V_Shukla•6m ago•0 comments

Courts Enjoin Internet Censorship Laws in Louisana and Arkansas

https://blog.ericgoldman.org/archives/2025/12/courts-enjoin-internet-censorship-laws-in-louisana-...
1•hn_acker•6m ago•0 comments

ChatGPT Was Beneficial for Google

https://twitter.com/BoringBiz_/status/2002115074975031605
1•jameslk•6m ago•0 comments

Show HN: A Simple Way to Track Business Subscriptions

https://www.chargenda.com/
1•brokeceo7•7m ago•0 comments

Confessions to a Data Lake

https://confer.to/blog/2025/12/confessions-to-a-data-lake/
1•kkl•7m ago•0 comments

OKAP (Open Key Access Protocol): Like OAuth, but for API Keys

https://okap.dev
1•init0•10m ago•1 comments

Shear-Zone Fractures Presage the Disintegration of Thwaites Eastern Ice Shelf

https://agupubs.onlinelibrary.wiley.com/doi/10.1029/2025JF008352
2•stevenjgarner•12m ago•1 comments

Show HN: analog.watch - read 3 analog clocks as fast as you can!

https://analog.watch
2•ezekg•13m ago•0 comments

Show HN: Random Word Generator–a simple tool for instant writing&naming prompts

https://randomwordgeneratorapp.top/en
1•bingbing123•15m ago•0 comments

Show HN: Wafer – Profile, inspect assembly, and iterate on CUDA within your IDE

https://www.wafer.ai/
2•technoabsurdist•15m ago•0 comments

Why Pancakes Taste Better from a Diner Than Homemade

https://www.thetakeout.com/2053498/why-pancakes-taste-better-from-diner-homemade/
2•speckx•22m ago•1 comments

I replaced my marketing stack with one autonomous AI system

https://vect.pro/
1•WoWSaaS•22m ago•1 comments

Tell HN: Festivus for the Rest of Us FestivusSavesTrees

1•SirLJ•23m ago•1 comments

The Architecture of Resistance

https://aneeshsathe.com/2025/12/22/the-architecture-of-resistance/
1•boredgargoyle•24m ago•0 comments

Towards a secure peer-to-peer app platform for Clan

https://clan.lol/blog/towards-app-platform-vmtech/
2•throawayonthe•24m ago•0 comments

Appropriate Uses for SQLite

https://sqlite.org/whentouse.html
2•whatisabcdefgh•25m ago•0 comments

Fabrice Bellard Releases MicroQuickJS

https://github.com/bellard/mquickjs/blob/main/README.md
93•Aissen•25m ago•4 comments

How Did Doge Disrupt So Much While Saving So Little?

https://www.nytimes.com/2025/12/23/us/politics/doge-musk-trump-analysis.html
6•JumpCrisscross•25m ago•0 comments

Microsoft: "Infinite Workday" Is Eroding Focus Time

https://focusflows.eu/blog/microsoft-infinite-workday
2•Ben_Tycho•28m ago•0 comments

AI Police Reports: Year in Review

https://www.eff.org/deeplinks/2025/12/ai-police-reports-year-review
2•hn_acker•28m ago•0 comments

Training the Idea Muscle: Riley Walz on creating viral internet pranks

https://sfalexandria.com/posts/rileys-ideas/
1•mellosouls•31m ago•0 comments

I built and deployed an AI agent to the cloud with live database in 5 minutes

https://www.neptune.dev/blog/build-and-deploy-an-ai-agent-to-the-cloud
1•dcodes•32m ago•0 comments

Just Use Elysia

https://justuseelysia.com
5•saltyaom•34m ago•0 comments