A recruiter pitched me a remote engineering role and asked me to review their codebase before the technical interview. The repo turned out to be a five-stage trojan that exfiltrates your environment variables and gives the attacker arbitrary code execution. Here's exactly what was in it, and the simple precaution that defeats the whole class.
Back to Blog
Security 6 min read
A LinkedIn Recruiter Sent Me Malware Disguised as a "Pre-Interview Code Review"
Vladimir Novick
May 4, 2026
Originally published on Dev.to: View original article →