I encountered this one personally - I was contacted on LinkedIn by someone interested in taking me on as a technical consultant. I agreed to meet with them. At the meeting, they asked me to clone their product's…
At the meeting, they asked me to clone their product's (public?!) repo and open it in Cursor or VSCode. I was immediately suspicious and refused. They disconnected and vanished from LinkedIn.
I took a look over the repo (without touching, of course) and spotted the exploit - VSCode will happily auto-run tasks listed in `tasks.json`. In this case, a task ran that harvested credentials from `process.env`, sent them to a remote server and then executed further code that the server sent back.
"Don't touch strange repos" isn't exactly revolutionary advice, but this isn't an exploit that I see talked about often - scammers are actively using it. It doesn't help that some recruiters are actually asking candidates to clone repos as part of their hiring process; if you're doing that, it's time to stop!
0 comments
No comments yet.
Related stories
- Hacker News · 3 points · 4 days ago
- Hacker News · 15 points · 15 days ago
- Launch HN: Vespper (YC F24) – SOTA Docx MCPvespper.comHacker News · 31 points · 4 days ago
- Hacker News · 1 points · 10 days ago
- Hacker News · 1 points · 4 days ago
- Hacker News · 1 points · 3 days ago