• ivan@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    20 days ago

    Damn, I thought LinkedIn itself got hacked, but that’s just “recruiter” trying to get people to install malicious npm modules. 🥱

    Good heads up tho, I periodically get folks trying some bullshit with me in there like “let’s talk on WhatsApp”.

    • LedgeDrop@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      19 days ago

      Yikes, this is spooky stuff.

      In the blog post, the author mentioned that their AI agent found the malicious payload.

      That reminded me of people writing malicious AI prompts. I find it shocking , that you really cannot trust 3rd party code and cannot safely use AI as a tool to quickly audit said code.

      I wonder if interviewing will come full circle and we’ll go back to resumes, phone interview, then in-person interviews. Rather, than the whole “take home project” crap (well… at least I have another reason to opt of them).

  • incentive@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    19 days ago

    I just went through this same deal on LinkedIn, only I told the “recruiter” I’d need to verify with the company this is standard practice (which I did, I emailed corporate). The account vanished within a few hours of me sending that msg. Same as the article, I reported the repo to GitHub and as far as I can tell the organization and accounts associated with it are still online.