horsefacts pfp
horsefacts

@horsefacts.eth

max was hit with a "contagious interview" attack. these are getting more sophisticated and very nasty. two good resources below to understand what they do. if you work in crypto you need to assume any Github repo you touch is from North Korea until proven otherwise. it sucks but if you are a dev your best protection is a totally isolated machine and intense discipline to keep it that way. if you're in an interview with someone you don't know, never ever run their code on your machine. if someone I interviewed pushed back if I asked them to clone a repo I would see it as nothing but a positive signal. https://opensourcemalware.com/blog/contagious-interview-vscode https://socket.dev/blog/north-korea-contagious-interview-npm-attacks
1 reply
15 recasts
56 reactions