Skip to content
Hacker News front page

A LinkedIn job offer that backdoors you on npm install

A backdoor in a LinkedIn job offer

A LinkedIn recruiter sent the author a GitHub repo to review. The repo hid a backdoor in app/test/index.js that triggers on npm install, fetching and executing remote commands from rest-icon-handler.store. Both the recruiter and the repo's commit author were impersonated—an arts journalist and an unwitting full-stack engineer. A read-only Pi agent flagged the payload in seconds. GitHub and LinkedIn had not acted at time of writing.

Why it matters: All three HKR axes hit. First-person experiment with a Pi agent finding a real npm backdoor, with concrete file paths and malicious URLs. Not a vendor case study — a dev's own story, which adds credibility. Capped below 85 because it's a personal security writeup, not an indus...

Read the original ↗Export Markdown