Original Summary

I encountered this one personally - I was contacted on LinkedIn by someone interested in taking me on as a technical consultant. I agreed to meet with them.<p>At the meeting, they asked me to clone their product&#x27;s (public?!) repo and open it in Cursor or VSCode. I was immediately suspicious and refused. They disconnected and vanished from LinkedIn.<p>I took a look over the repo (without touching, of course) and spotted the exploit - VSCode will happily auto-run tasks listed in tasks.json. In this case, a task ran that harvested credentials from process.env, sent them to a remote server and then executed further code that the server sent back.<p>&quot;Don&#x27;t touch strange repos&quot; isn&#x27;t exactly revolutionary advice, but this isn&#x27;t an exploit that I see talked about often - scammers are actively using it. It doesn&#x27;t help that some recruiters are actually asking candidates to clone repos as part of their hiring process; if you&#x27;re doing that, it&#x27;s time to stop!


  • 情报分类:工作与职业机会
  • 分类依据:内容涉及招聘、求职或职业发展
  • 信息来源:Hacker News 新项目
  • 发布时间:2026/10/2 17:13:37