2 min read
Fake Job Recruiters Hid Malware In Developer Coding Challenges
rss.slashdot.org
Sunday, February 15, 2026
"A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks," reports the Register. Researchers at software supply-chain security company ReversingLabs say that the threat actor creates fake comp...
"A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks," reports the Register.
Researchers at software supply-chain security company ReversingLabs say that the threat actor creates fake companies in the blockchain and crypto-trading sectors and publishes job offerings on various platforms, like LinkedIn, Facebook, and Reddit. Developers applying for the job are required to show their skills by running, debugging, and improving a given project. However, the attacker's purpose is to make the applicant run the code... [The campaign involves 192 malicious packages published in the npm and PyPi registries. The packages download a remote access trojan that
can exfiltrate files, drop additional payloads, or execute arbitrary commands sent from a command-and-control server.]
In one case highlighted in the ReversingLabs report, a package named 'bigmathutils,' with 10,000 downloads, was benign until it reached version 1.1.0, which introduced malicious payloads. Shortly after, the threat actor removed the package, marking it as deprecated, likely to conceal the activity... The RAT checks whether the MetaMask cryptocurrency extension is installed on the victim's browser, a clear indication of its money-stealing goals...
ReversingLabs has found multiple variants written in JavaScript, Python, and VBS, showing an intention to cover all possible targets.
The campaign has been ongoing since at least May 2025...
Read more of this story at Slashdot.
Read the full article
Continue reading on rss.slashdot.org
More from rss.slashdot.org
1 hours ago
На встрече Совета мира объявят о сумме на восстановление Газы, заявил Трамп
1 hours ago
"Задушит Союз". На Западе запаниковали после нового требования Зеленского
1 hours ago
Babies at nursery shape each other’s microbiomes

1 hours ago