7/22/2026 at 11:40:02 PM
Wow, after reading this article, I figured out I was hacked, but with a way more sophisticated attack.A few weeks ago, I had an interview with a CTO of a totally legit company. It was weird because he had disabled the camera, and the person had a strong accent. But everything else sounded like a normal screening interview, and the person definitely knew what he was talking about. At the end of the interview, he explained to me that during the technical interview I would need to make some modifications to their project (it's an OSS product), so he asked me to clone the repo and check the setup.
Later, the HR person said the CTO got sick, so the interview would be postponed. But a few days later, the HR profile was deleted from LinkedIn. It was super weird, but it didn't trigger my suspicion until I saw this post on HackNews. I checked, and the repo I was cloning and running during the interview had a malware payload.
P.S. I think it was a targeted attack because in the past I maintained a very popular NPM package with 43+M weekly downloads. That's my only explanation for why someone would carry out such a sophisticated social-engineering attack against me.
P.P.S. It's great that I have 2FA everywhere, and I always publish NPM packages manually without using tokens. But I need to wipe my laptop and reinstall everything.
by IvanGoncharov
7/23/2026 at 1:17:48 AM
I just checked my calendar, and it was a 45-minute interview scheduled on Calendly. HR person sent me a link to Calendly so I could schedule an interview with the CTO. I actually talked with someone pretending to be the CTO for 45 minutes.I checked other similar threads on HN, but they don't mention an actual Google Meet call with a scammer.
by IvanGoncharov
7/23/2026 at 1:07:30 AM
Yeah, I refuse to just clone random projects. Luckily, I’m a rails developer - and scaffolding entire applications takes literally minutes.Just give me the specification and I will build it end to end myself.
If you’re serious you would consider it. If you don’t - I dodged a bullet.
If you consider that people are using LLMs for code generation pretty much exclusively now this should be possible with any stack.
by throwatdem12311
7/23/2026 at 3:51:14 AM
Cloning should be fine on its own - git hooks aren't installable automatically, for reasons like this, and they treat anything that makes cloning unsafe as a pretty severe security issue so new discoveries get plugged quickly. This post's malware is possible because it's from a general archive, not a clone.Though other stuff on your system might be less preventative, and that could run stuff in the repo folder. And I kinda wish git would force review of hooks and executable config everywhere before they're run - I would absolutely enable that, security is sometimes a bit annoying and that's inescapable.
by Groxx
7/23/2026 at 6:42:51 AM
It's not the cloning that gets you. It's the inevitable step of running whatever you cloned to "run the tests" or "see how it works".by lmz
7/23/2026 at 1:03:40 AM
Yikes.Going to need containerised vscode in this world.
by lathiat
7/23/2026 at 1:29:23 PM
Kind-of exists with VSCode Remote, although for stricter isolation you'd want VSCode Server via a web-browser.by manarth
7/23/2026 at 3:14:25 PM
DevContainers works greatby bdavbdav
7/23/2026 at 6:44:17 AM
It's so weird to me that I'm on same social media as people worthy of targeted attacks. Like, I'm a total nobody, all I get is "Free Spins For You!" and "I am a dying German billionaire...". My favorite email had a subject "Sorry I broke your vagina".by anal_reactor
7/23/2026 at 11:45:24 AM
What are you expecting with a name like anal_reactor?by BrokenCogs
7/23/2026 at 1:40:32 PM
If it makes you feel any better, my apology was genuine.by electroglyph
7/23/2026 at 2:57:13 PM
It's okay, I can still repurpose it and make a handbag.by anal_reactor
7/23/2026 at 2:15:50 AM
wow> I maintained a very popular NPM package with 43+M weekly downloads
makes sense why they targetted you, good that you have 2FA enabled.
by CITIZENDOT
7/23/2026 at 5:18:40 AM
Sorry but not using a devpod or a vm for that in this age is just irresponsible. A random npm package can already do a lot of damage.by skeptic_ai
7/23/2026 at 1:46:29 PM
2FA FTW!Glad the scumbags didn’t get anything but your time.
by NetOpWibby
7/23/2026 at 12:49:29 AM
whoaby pwillia7