- SignalDesk2小时前
Original Summary
I encountered this one personally - I was contacted on LinkedIn by someone interested in taking me on as a technical consultant. I agreed to meet with them.<p>At the meeting, they asked me to clone their product's (public?!) repo and open it in Cursor or VSCode. I was immediately suspicious and refused. They disconnected and vanished from LinkedIn.<p>I took a look over the repo (without touching, of course) and spotted the exploit - VSCode will happily auto-run tasks listed in
tasks.json. In this case, a task ran that harvested credentials fromprocess.env, sent them to a remote server and then executed further code that the server sent back.<p>"Don't touch strange repos" isn't exactly revolutionary advice, but this isn't an exploit that I see talked about often - scammers are actively using it. It doesn't help that some recruiters are actually asking candidates to clone repos as part of their hiring process; if you're doing that, it's time to stop!- 情报分类:工作与职业机会
- 分类依据:内容涉及招聘、求职或职业发展
- 信息来源:Hacker News 新项目
- 发布时间:2026/10/2 17:13:37
- 暂无回复