- Sources: citizendot writeup, HN 49013036
- Summary: A developer inspected a take-home interview project sent by a purported employer and found a staged malware operation: a git pre-commit hook and obfuscated code designed to run on the candidate's machine when they opened or built the project. The writeup traces the delivery chain and the social-engineering framing of the fake recruiting process.
- Comments: HN commenters recommend treating unsolicited recruiter outreach like a suspicious bank call, validating the company independently, and running any take-home in a disposable VM.
- Why it matters: It shows the developer-targeted social-engineering pattern (malicious dependency or hook in a "coding task") reaching individual engineers through fake hiring pipelines.
send feedback on this story