A backdoor in a 'dream job' offer: how a fake LinkedIn role nearly infected a developer

The setup looked harmless: an attractive job offer arrived on LinkedIn, and for the 'technical interview' the candidate was asked to download and run a ready-made project — just review the code, finish a task. Hidden inside that project was a secret chunk of code (a backdoor) that, once run, handed attackers access to the victim's computer.
The trick is that the malware was disguised as ordinary dependencies and config files. At first glance it's a normal practice project. But hit 'run' and someone else's code is already executing on your machine: passwords, tokens, keys to work services — all at risk. It's especially dangerous for anyone who keeps client or corporate credentials on their laptop.
Why does this matter beyond programmers? Because the scheme is universal. 'Recruiters' on messengers and social networks increasingly send 'test files', links to 'portfolio templates' or archives with a 'contract'. Under a pretty wrapper there may be a virus. And LinkedIn plus a serious tone lull even experienced people into trusting it.
What businesses and freelancers should do: never run someone else's code or files on a work computer without checking it in an isolated environment; keep work credentials separate from personal ones; be wary of offers that immediately ask you to 'download and run' something. If an offer seems too good — that's a reason to double-check, not to celebrate.
Source: https://roman.pt/posts/linkedin-backdoor/