A recent investigation by Elastic Security Labs shows how fake developer interviews are becoming an effective malware delivery technique.
Attackers distributed fully functional Next.js coding assignments while hiding malware payloads inside SVG files. Once executed, the project could steal browser credentials, crypto wallet data, cloud tokens, and developer secrets.
This article explores how the attack worked, why traditional checks didn't catch it, and why developers should isolate unfamiliar coding assignments before running them.
Read the full article:
https://blog.invidelabs.com/elastic-fake-coding-test-svg-malware/
Top comments (0)