At the meeting, they asked me to clone their product's (public?!) repo and open it in Cursor or VSCode. I was immediately suspicious and refused. They disconnected and vanished from LinkedIn.
I took a look over the repo (without touching, of course) and spotted the exploit - VSCode will happily auto-run tasks listed in `tasks.json`. In this case, a task ran that harvested credentials from `process.env`, sent them to a remote server and then executed further code that the server sent back.
"Don't touch strange repos" isn't exactly revolutionary advice, but this isn't an exploit that I see talked about often - scammers are actively using it. It doesn't help that some recruiters are actually asking candidates to clone repos as part of their hiring process; if you're doing that, it's time to stop!
0 comments