Security · 1h ago
Fake Job Interview Project Installs Malware via Git Hook
A developer discovered that a take-home interview project contained a malicious Git hook designed to exfiltrate data. The hidden script ran automatically when cloning the repository, targeting SSH keys and credentials. The incident highlights a growing trend of attackers using fake job offers to compromise developers.
Meridian48 take
This attack vector exploits trust in the hiring process, but the real story is how easily developers overlook repository inspection before running code.
Read the full reporting
I Inspected My Take-Home Interview Project. It Was a Whole Operation →
Hacker News
supply-chain-attackdeveloper-security