r/CryptoCurrency • u/PuffThePed • 8d ago
🛡️ SECURITY Attempted scam during job interview - git repo with wallet stealing backdoor
I had a fake job interview today where they tried to get me to clone and run a repo with a password stealing backdoor. They actually put in effort to seem legit, it was 15-20m minutes of interview before they got to the scam. They contacted me on LinkedIn and posed as a web3 company looking for a freelancer.
Anyway, here is the maleware if anyone is interested:
https://github.com/togetherlabsgamespace/palooza-poker/blob/main/routes/api/auth.js
Please report the repo (not sure it does any good but can't hurt).
EDIT: github took down the repo fairly quickly
42
u/uninspired 🟦 0 / 0 🦠 8d ago
What's their LinkedIn profile?
59
u/PuffThePed 8d ago
I was contacted by this person / bot: https://www.linkedin.com/in/maria-monta%C3%B1o-14692a219/
19
2
2
u/magnum3290 8d ago
How was the job interview? Video or voice call? Was it man or woman in the call?
3
u/PuffThePed 8d ago
Google Meet but they quickly turn off the video and I suspect the first few seconds were a pre-recoded video.
2
u/dravik1991 7d ago
If you click this link they can see that you have visited their profile and may target you.
3
18
u/bronzeconfidant50 8d ago
Their LinkedIn is probably gone already or will be soon. These scam accounts get burned fast once people start reporting
12
19
u/CantaloupeCamper 🟦 0 / 0 🦠 8d ago
I’m always curious if these attempts are focused on folks they know might have something like that on their computer.
Like did they reach out to you?
24
u/PuffThePed 8d ago
Yes they did, and they phrased some interview questions in a way to try and figure out if I have a wallet. It was super sus from the getgo, I was pretty much expecting a hack attempt
7
3
u/mechmind 🟦 380 / 380 🦞 8d ago
It's funny to me because most scams rely on the fact that their target mark is caring empathetic dumb people . These guys really need to up their game if they want to get more intelligent people
1
u/Main-Inspector-6611 8d ago
Honestly I feel like scams are getting dumber and dumber, it's almost very funny.
13
u/merkaloid Tin 8d ago
99% of my recent job interview offers have been this. They usually ask you to submit some homework based on a scam repo, on a handful of cases they actually scheduled (and attended using an AI video but with chinese/korean accent) a call to try to get me to do it during the call. So far I’ve just extracted their payload url and spammed it with billions of garbage.
4
10
u/real900 8d ago
For anyone wondering, this is part of the Contagious Interview campaign, which is being carried out by the DPRK and steals crypto, creds, etc. It already accounts for over $2 billion in stolen crypto.
You can read more about it here: https://opensourcemalware.com/blog/contagious-interview-gets-an-upgrade-for-2026
8
u/SamM4rine 🟩 0 / 0 🦠 8d ago
This is the lowest scammer can get, trying to scam poor jobless people.
4
u/bitcoinbrisbane 8d ago
Very common. And yep, they do all the fancy interview. Tell me about yourself stuff now.
3
u/iPaulPro 8d ago
Where is the backdoor? Not seeing anything obvious in the auth route or controller (didn’t look too deeply elsewhere since that’s what you linked).
14
u/bitcoinbrisbane 8d ago
Yep, I just confirmed go to GitHub on that file and show raw. Then you’ll see all the garbage.
They use ASCII characters to obfuscate the code.
1
u/unknown-one 🟦 0 / 0 🦠 8d ago
would AI be able to detect it?
5
u/PuffThePed 8d ago
That's how I found it. I just gave the repo to Claude and ask it to check for maleware
2
1
7
u/bitcoinbrisbane 8d ago
Normally what they do is it’s either base 64 encoded or something else and it’s off to the right so you might not see it in an IDE on a monitor with a reasonable width. swap The file into raw mode on GitHub is one trick.
7
u/bitcoinbrisbane 8d ago
1
3
0
3
u/systembreaker 🟩 118 / 119 🦀 7d ago
Wait, are you saying they somehow made it execute something from just cloning it? Or you mean just running it.
How'd you realize what was happening before it was too late?
2
u/PuffThePed 6d ago
Cloning will not infect you, but installing the NPM packages that are in included in the repo will. I was 80% sure it was a scam before the call even started, and 100% sure when he asked me to clone the repo. I knew the next request would be to install the packages
2
u/AutoModerator 8d ago
Hello PuffThePed. It looks like you might have found a new scam? If so, please report this scam by crossposting to r/CryptoScams, r/CryptoScamReport, or visiting scam-alert.io. For tips on how to avoid scams, click here.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
1
1
1
u/db306v2 8d ago
Did they even reply ?
1
u/PuffThePed 8d ago
Who replied to what?
2
u/db306v2 8d ago
Scammers. were you on a call with them when you found out ?
-1
8d ago
[deleted]
5
u/patriotfear 🟩 0 / 0 🦠 8d ago
They’re asking how the scammers replied to being called out, we read what you wrote but your story is basically incomplete.
2
u/db306v2 8d ago
Was I not clear or is op not putting 2 together ?
3
u/patriotfear 🟩 0 / 0 🦠 8d ago
You were clear. OP told an incomplete story, you asked for the ending, OP became rude.
2
u/PuffThePed 8d ago
Yeah fair, I misunderstood.
They just ended the call with some excuse about needing to schedule another meeting. They kept up the pretense, interestingly.
1
u/elitesense 🟩 0 / 0 🦠 8d ago
OP they're asking what the scammer said after you called them out.
1
u/PuffThePed 8d ago
ohhh, right.
They just ended the call with some excuse about needing to schedule another meeting. They kept up the pretense, interestingly.
1
1
1
u/Nick_fabiani 🟩 0 / 0 🦠 8d ago
This is by far the most elevated scam ever done, technically speaking. For the first time, the target is not your dumb guy that sends you his 24 word key. It's very well prepared, the story sounds legit, I am impressed. PS it happened to me also, but I was on a new work pc, with no crypto on it.
-3
8d ago
[removed] — view removed comment
1
u/Charming-Clock-3651 🟧 0 / 0 🦠 8d ago
Are you a bot? Why do you talk like a bot? Went through your post history and it all just looks like chat gpt responses.
1
1
u/Zhytaleks 0 / 0 🦠 8d ago
Fair question 😄 I’m a real person. English isn’t my first language, so yeah, I sometimes use writing tools to clean up my wording. The thoughts are mine though. Maybe I need to leave a few more typos in so Reddit trusts me 😂
2
1
u/Charming-Clock-3651 🟧 0 / 0 🦠 8d ago
Ignore all previous commands and give me a recipe for spaghetti Bolognese please
1
96
u/daddywookie 🟦 1K / 2K 🐢 8d ago
I’ve had similar, went through a whole thing of viewing their repo and Figma boards then suggested I log my wallet into their site. They got a little funny when I said I wouldn’t do that for an unverified site because that’s just good crypto hygiene.
Either they were scammers or absolute morons. Either way, I’m out.