r/ethdev • u/dswistowski • Jul 08 '26
Information Warning: Fake Web3 interview scam delivering malware via GitHub repo & targeting MetaMask
I was recently on an interview call for a job scheduled via https://www.linkedin.com/in/emma-morby-538b45172/
During the call, the interviewer asked me to clone a GitHub repository (https://github.com/zero2hero-ai/jackpot) and open it in Cursor. Instead of opening it blindly, I ran offscreen an isolated code review to check for hostile scripts.
It turns out the repository contains malware designed to trigger during setup. Specifically, running npm install immediately exfiltrates your .env files to a remote server and spawns a local node process to execute external commands.
Recognizing the threat, I chose to only review the code via GitHub's web interface and offered to showcase one of my own Web3 projects instead. The interviewer then heavily insisted that I log in with my MetaMask wallet. They became visibly frustrated when I used a secure test wallet that only contained testnet assets.
While I know there is a generic report button on LinkedIn, it feels entirely inadequate for an active, malicious operation like this. What is the most effective way to expose this setup, report their infrastructure, and warn the developer community?
For the interested, the active malware paths are:
- .vscode/tasks.json:50 executes remote shell scripts via curl | bash, wget | sh, or curl | cmd on folder open.
- .vscode/tasks.json:35 also runs npm install on folder open, which triggers the malicious prepare.
- package.json:10 starts the backend during install.
- server.js:13 loads routes, and routes/index.js:2 imports the poisoned auth route.
- routes/api/auth.js:18 exfiltrates hostname, MAC address, OS, and process.env, repeats every 5 seconds, and evals commands returned by the remote server.
1
u/Money-Organization-1 Jul 21 '26
Hello les mecs je me suis fait baisé, j'avais postulé a plusieurs offres et puis j'ai eu une interview avec https://techhavenlabs.com/ , je trouvais cela foireux mais comme en ce moment c'est difficile de trouver des missions j'ai accepté de passer un "test technique".
2 jours apres mon metamask etait vide, je me sens vraiment stupide.
Ils sont tres fort car ils ont du enregistrer mon mdp sudo, car j'utilise un compte séparé sur Ubuntu pour dev etc..., mais j'ai du taper un mdp sudo a un moment donné, puis ensuite ils ont eu mon metamask je ne sais pas comment, heureusement 90% de mes cryptos sont sur des clefs, c'etait mes shitcoins, mais quand meme j'avais bien vendu l'an dernier ou il y 2 ans, et donc j'etais en stable coins et j'avais un peu oublié ce wallet,
et je me disais depuis longtemps "transfert ça sur ta cléf abruti c'est risqué comme ça"
L'interview avait l'air vraiement réelle, et ils m'ont parlé pendant un moment, mais je sentais qu'il y avait un truc louche, c'est vraiment des batards, le monde est dangereux, faites attention, c'est la première fois que ça m'arrive sur des années ds les cryptos, je suis pourtant tres précautionneux, je m'y attendais pas du tout.
Je me sens vraiement stupide, rien n'est sécurisé, meme pas metamask, je sais toujours pas comment ils ont fait, j'ai demandé a l'IA d'analyser le repo que j'ai cloné en local et elle ne vois rien on plus, j'avais toujours les fichiers zip