A developer discovered a malicious coding test during a job interview process. The repository contained VSCode tasks that executed remote shell scripts, downloading and running malware on the candidate's machine. The attack used multiple Vercel-hosted domains to fetch and execute scripts with JWT tokens. The author investigated

3m read time From runjak.codes
Post cover image
Table of contents
PreludeEnter SolvolabsThe smoking gunA quick investigationReportingClosing notes

Sort: