frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

I Inspected My Take-Home Interview Project. It Was a Whole Operation

https://citizendot.github.io/articles/fake-job-interview-git-hook-malware/
164•CITIZENDOT•1h ago

Comments

ChrisMarshallNY•1h ago
I assume these types of things are going to become more and more common.

Looks like these folks really did their homework.

It's nasty, but I have to respect their skills. I'll bet it works, quite often.

LoganDark•54m ago
Their "skills" might just be borrowed from some LLM.
throw_m239339•50m ago
Yeah, this scam is probably all automated at first place. Welcome to the "agent era"...
ChrisMarshallNY•31m ago
I dunno. The Norks seem to be really good at this, and have been, for a long time.

I suspect it's clever, experienced, engineers, leveraging LLMs.

CITIZENDOT•49m ago
yea, i had fun looking around, this felt like a ctf challenge lol. if they had any vuln on their server, it would've been even better.
gtowey•52m ago
My takeaway from this is that I should use the same defense as when someone calls you "from you bank". When they reach out directly, go to the real company's site to apply and contact a real recruiter. If you can't validate that the business is legit before, then assume malfeasance.
technion•44m ago
Companies make this hard, a bit like various email scams where legit company communication comes from seemingly random domains (hello paypal). Often the company is legit, but theres no public contact that knows anything about the recruiter thats working for them.
bombcar•41m ago
Healthcare companies are the WORST at this - they will send you legitimate email from h34lthc4re.biz with a heart-happy-health.phishing.info link that you HAVE to use - and it's all legit.
paxys•39m ago
Even if the attempt is legit, going to the company’s website/careers page to try and reach them is pointless. You application will just get lost among the thousands of others. Your best bet is to ask the recruiter to email you and check for a @<company.com> email address. And even if the attempt checks out don’t run untrusted code on your machine.
yieldcrv•32m ago
it was in this moment, that gtowey’s outdated job solutions transitioned them from unc to boomer
ge96•52m ago
There was a funny video I saw recently someone's running Red Star OS on their computer and a scammer is trying to scam them thinking it's Windows

Unrelated to this git pre commit hook attack but yeah

rdksu•48m ago
Bruh the harry potter theme song scared the shit out of me as it turned itself on. Bad UX for a personal site. Great article btw !
CITIZENDOT•42m ago
sorry, i added it to set the mood for my site :') yk, like moving lamps at the top, hanging dementor at the right side (only visible on desktops).

should i remove it?

ikistuach•40m ago
yes
eightysixfour•38m ago
No, it made me laugh.
john_strinlai•31m ago
>should i remove it?

there is no place for fun, whimsy, moods, or personalization on the web. sorry.

(no, at least not at the request of random internet stranger #10545346)

ChrisMarshallNY•11m ago
Around here, many people have their sense of humor, removed, during their first colonoscopy.

I joke, anyway, and bear the downvotes. Totally worth it.

Lammy•
nphardon•42m ago
always a good day when we get an a post on front actually related to hacking on hackernews.
wxw•36m ago
> They embedded a script that checks the victim’s host operating system and silently executes a remote payload.

Seems like this is becoming a recurring theme, similar story was on the front page last month.

https://news.ycombinator.com/item?id=48546294

guessmyname•30m ago
> […] and silently executes a remote payload

Silently only because @OP is not running Little Snitch (or the equivalent on Windows/Linux).

I’m in the habit of running `tree -a` or the more modern `erd --hidden` but in this case I wouldn’t have needed to, and I wouldn’t have had to audit the scripts either. Little Snitch would have popped up an alert the moment cURL tried to reach that remote server, which is obviously suspicious, and I would have ended the “interview” right there.

darth_avocado•21m ago
If LinkedIn actually cared about preventing scams, they could implement verification using company emails if you want to list your current employment. And if it is too much of a heavy burden, then at the minimum you should have it as an optional feature that recruiters would have to comply with, if they want to be legitimate.
CITIZENDOT•13m ago
> they could implement verification using company emails

they added this back in 2023 (https://news.linkedin.com/2023/april/linkedin-s-new-verifica...), but very less people actually bother to verify with their email, so not having it doesn't always mean it's illegitimate.

darth_avocado•10m ago
The legitimate recruiters should start using it then.
lantry•17m ago
> Side note: Why use a raw IP address? If anything, this screams “malware.” At least register a decoy domain like lint-checker.com or jenkins-ci-runner.net. If the threat actors who wrote this are reading: take notes people!

Maybe they don't want to give any identifying info to the domain registrar? Or just minimizing their online presence?

CITIZENDOT•9m ago
fair point
sailfast•8m ago
Really hate that the USG overreaction on Fable has given us a neutered version of AIs for DEFENSIVE capabilities even when we just want an explanation of what we’re being subjected to with this malware.

Give defenders a better shot…

drnick1•3m ago
Are these kinds of tests still relevant in the AI age? Genuine question, I have not interviewed for a very long time.
gtowey
•
17m ago
I think you misunderstood.

I'm not talking about switching to cold contacting companies as a job hunting strategy. I'm saying if you get a suspicious outreach from a rando on linked in on behalf of a company THEN you only continue if you can reach out to the same person via official company channels.

30m ago
Middle ground: make it respect `prefers-reduced-motion` :)
seanobannon•27m ago
absolutely not! it is a delightful source of whimsy on an increasingly uniform web
projektfu•19m ago
No, it's your playground. My podcast was talking about the music the guest was making and I thought he was playing something Potter related.
aftbit•13m ago
I used developer tools to delete the dementor, then I muted the site when it started playing music.
ladybro•34m ago
Where can one be whimsical and fun if not for a personal site?

Terrence Tao's ChatGPT Conversation about the Jacobian Conjecture Counterexample

https://chatgpt.com/share/6a5fdc7a-d6f8-83e8-bbea-8deb42cfed56
460•gmays•4h ago•255 comments

GigaToken: ~1000x faster Language model tokenization

https://github.com/marcelroed/gigatoken/
279•syrusakbary•4h ago•51 comments

Malleable Computing, Emacs, and You

http://yummymelon.com/devnull/malleable-computing-emacs-and-you.html
31•kickingvegas•56m ago•3 comments

Safari Technology Preview 248 Released

https://webkit.org/blog/18162/release-notes-for-safari-technology-preview-248/
36•Erenay09•1h ago•4 comments

Show HN: Bento - An entire PowerPoint in one HTML file (edit+view+data+collab)

https://bento.page/slides/
564•starfallg•6h ago•131 comments

Are AI Labs Pelicanmaxxing?

https://dylancastillo.co/posts/pelicanmaxxing.html
288•dcastm•4h ago•118 comments

Quality non-fiction books are the antithesis of AI slop

https://resobscura.substack.com/p/quality-non-fiction-books-are-the
19•benbreen•7h ago•3 comments

John C. Dvorak has died

https://twitter.com/na_announce/status/2079952538040672302
348•coleca•2h ago•82 comments

Medici family mystery may be solved after more than 400 years

https://www.cnn.com/2026/07/15/science/medici-family-mystery-dna-malaria
11•effects•16m ago•0 comments

Everyone Should Know SIMD

https://mitchellh.com/writing/everyone-should-know-simd
158•WadeGrimridge•4h ago•46 comments

Any text-to-SQL benchmark should address difficulties of real-world data stores

https://cacm.acm.org/blogcacm/if-you-think-you-can-do-real-world-text-to-sql/
9•shenli3514•17m ago•0 comments

Nobody knows what a used GPU cluster is worth

https://ciphertalk.substack.com/p/nobody-knows-what-a-used-gpu-cluster
131•rbanffy•1w ago•107 comments

Making

https://beej.us/blog/data/ai-making/
235•erikschoster•6h ago•98 comments

I Inspected My Take-Home Interview Project. It Was a Whole Operation

https://citizendot.github.io/articles/fake-job-interview-git-hook-malware/
165•CITIZENDOT•1h ago•36 comments

Taking OCaml and Eio for a Spin

https://mattjhall.co.uk/posts/taking-ocaml-eio-for-a-spin.html
23•mattjhall•2d ago•2 comments

The startup's Postgres survival guide

https://hatchet.run/blog/postgres-survival-guide
278•abelanger•9h ago•151 comments

Launch HN: Unlayer (YC W22) – Add email and document builders to your app

https://unlayer.com
38•adeelraza•6h ago•22 comments

Nvidia DGX Spark as a daily driver

https://daniel.lawrence.lu/blog/2026-07-15-dgx-spark-as-daily-driver/
59•plun9•3d ago•42 comments

Fairphone 6 wide camera experimental Linux support

https://nondescriptpointer.com/articles/fairphone-6-wide-camera-linux/
19•helonaut•1h ago•0 comments

Ghost Cut – or why Cut and Paste is broken everywhere

https://ishmael.textualize.io/blog/ghost-cut/
108•willm•7h ago•77 comments

Businesses with ugly AI menu redesigns

https://blog.fiddery.com/businesses-with-ugly-ai-menu-redesigns/
145•speckx•9h ago•117 comments

So Reddit has decided that plain HTML is unsafe

https://www.cole-k.com/2026/07/21/reddit/
159•montroser•9h ago•179 comments

Can a MUD evaluate LLMs? A $99 proof of concept

https://cruciblebench.ai/
83•Davisb135•6h ago•50 comments

Why do we love music? (2018)

https://pmc.ncbi.nlm.nih.gov/articles/PMC6353111/
7•jstrieb•2d ago•0 comments

Back to Kagi

https://blog.melashri.net/micro/back-to-kagi/
156•speckx•9h ago•142 comments

Mechanical light bulb from 1675 [video]

https://www.youtube.com/watch?v=0Y-9GbsS9Fg
64•kadohg•1w ago•34 comments

Does creatine make you smarter?

https://dynomight.net/creatine/
225•surprisetalk•6h ago•209 comments

10 REM"_(C2SLFF4

https://beej.us/blog/data/mystery-comment/
150•ingve•10h ago•42 comments

Which streaming service was that on again?

https://www.timwehrle.de/blog/which-streaming-service-was-that-on-again/
32•weetii•7h ago•55 comments

“We have information that Moonshot distilled Fable for the development of K3”

https://twitter.com/mkratsios47/status/2079933645888880708
191•softwaredoug•7h ago•487 comments