Hacker News
How to compromise your system with a job interview
A recruiter on LinkedIn sent a “relevant opportunity” that was actually a phishing scheme, providing a 180-file TypeScript project hosted on Bitbucket. The code executes a loader that downloads obfuscated JavaScript from jsonbin.io, which then contacts a C2 server and installs a RAT capable of spawning shells, stealing credentials, wallet data, screenshots, and exfiltrating environment variables such as MONGO_URI and JWT_SECRET.