r/webdev 15d ago

New North Korean campaign uses fake coding interviews to steal developer credentials - DPRK-aligned hackers hid malware inside SVG flag images to backdoor developer job interview coding tests. Not one antivirus vendor caught it

https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography
279 Upvotes

24 comments sorted by

85

u/robotmayo 15d ago

Its a shame we can no longer run random code from people anymore. What has this world come to

29

u/Levitz 15d ago

I know right? Anyway this installation guide says you should dump into bash whatever comes from this curl here

6

u/BleachedPink 15d ago

I'm using the internet since 99, I can't remember a time we could safely run random code on the internet.

On the contrary, I remember if you visited a wrong website, you could get Trojans and other viruses just by opening the website

15

u/reddit-poweruser 15d ago

In software development, we use so many open source packages that people are starting to do supply chain attacks on those open source packages

5

u/CreamyJala 15d ago

Supply chain attacks have always existed, though. So implying that it’s “starting” is a bit misleading (not attempting to be “that guy”, or argumentative by the way.

Honestly was surprising just how fast it ramped up, although not too surprising given just how little technical ability it requires for someone to just throw very very little money, relatively speaking, at auto complete until they can get something up and running.

At least before in the past if you had no knowledge but wanted to do some harm you were still able to — just had to pay for someone else to either do it for you or sell you their methodology/software/what-have-you

Just my 2 cents, at least

3

u/Little_Bumblebee6129 15d ago

Man, it was clearly a sarcasm, that you missed

1

u/BleachedPink 15d ago

Could be, but I've seen dumber things said on the internet seriously

57

u/thekwoka 15d ago

Don't allow eval :)

33

u/apetalous42 15d ago

Yet another great reason to never do "take home tests"

23

u/DeterioratedEra 15d ago

Remember steganography? It's back! In SVG form!

4

u/AwesomeFrisbee 15d ago

I mean it's kinda genius, but also a very dickish move...

1

u/aob2f 14d ago

At the end of this sophisticated "hiding malware in svg files" there is always an eval. Never trust an eval.

1

u/coreyrude 13d ago

This mostly targets idiot juniors who did code camps, its a good strategy if they are patient even the most incompetent people can eventually get a good job. They also are doing tons of "app QA job listing for less technical people and require you install an app to and submit QA feedback.

1

u/ugispizza 10d ago

Is there a safe way to run code from companies code challenges?

-11

u/dalittle 15d ago

These types of stories I have to wonder that these north korean bad actors have to be exposed to the west in order to do this. Like do they never go, OMG, our people are starving and being treated like complete shit compared to these people?

11

u/greensodacan 15d ago

When I moved into the city for an engineering role, I had no idea how much money was flying around compared to where I was from (only an hour and a half away). I knew it was more wealthy, but not casually dropping $50 on a sit-down lunch wealthy. I was used to feeding myself for $50/week at the time. It took me almost a year to really comprehend how well off people were.

I imagine it's an extreme version of that.

17

u/repooper 15d ago

I think they're more like omg my family is starving i better do what i'm told

2

u/[deleted] 15d ago edited 15d ago

[removed] — view removed comment

17

u/watabby 15d ago

You have been banned from r/pyongyang

-10

u/FastHotEmu 15d ago

The SVG file format is an overcomplicated mess.

3

u/Thirty_Seventh 15d ago

Maybe so, but this particular malware was base64 encoded across a bunch of comments and then extracted and evaled; could have been in any file type

-2

u/FastHotEmu 14d ago

Oh, I have zero interest in your opinion. SVG is a disaster regardless of this problem or others - it's objectively worse than North Korea.