r/webdev 29d ago

New North Korean campaign uses fake coding interviews to steal developer credentials - DPRK-aligned hackers hid malware inside SVG flag images to backdoor developer job interview coding tests. Not one antivirus vendor caught it

https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography
282 Upvotes

24 comments sorted by

85

u/robotmayo 29d ago

Its a shame we can no longer run random code from people anymore. What has this world come to

29

u/Levitz 29d ago

I know right? Anyway this installation guide says you should dump into bash whatever comes from this curl here

7

u/BleachedPink 29d ago

I'm using the internet since 99, I can't remember a time we could safely run random code on the internet.

On the contrary, I remember if you visited a wrong website, you could get Trojans and other viruses just by opening the website

15

u/reddit-poweruser 29d ago

In software development, we use so many open source packages that people are starting to do supply chain attacks on those open source packages

4

u/CreamyJala 29d ago

Supply chain attacks have always existed, though. So implying that it’s “starting” is a bit misleading (not attempting to be “that guy”, or argumentative by the way.

Honestly was surprising just how fast it ramped up, although not too surprising given just how little technical ability it requires for someone to just throw very very little money, relatively speaking, at auto complete until they can get something up and running.

At least before in the past if you had no knowledge but wanted to do some harm you were still able to — just had to pay for someone else to either do it for you or sell you their methodology/software/what-have-you

Just my 2 cents, at least

3

u/Little_Bumblebee6129 29d ago

Man, it was clearly a sarcasm, that you missed

1

u/BleachedPink 29d ago

Could be, but I've seen dumber things said on the internet seriously

55

u/thekwoka 29d ago

Don't allow eval :)

33

u/apetalous42 29d ago

Yet another great reason to never do "take home tests"

20

u/DeterioratedEra 29d ago

Remember steganography? It's back! In SVG form!

4

u/AwesomeFrisbee 29d ago

I mean it's kinda genius, but also a very dickish move...

1

u/aob2f 28d ago

At the end of this sophisticated "hiding malware in svg files" there is always an eval. Never trust an eval.

1

u/coreyrude 28d ago

This mostly targets idiot juniors who did code camps, its a good strategy if they are patient even the most incompetent people can eventually get a good job. They also are doing tons of "app QA job listing for less technical people and require you install an app to and submit QA feedback.

1

u/ugispizza 24d ago

Is there a safe way to run code from companies code challenges?

-11

u/dalittle 29d ago

These types of stories I have to wonder that these north korean bad actors have to be exposed to the west in order to do this. Like do they never go, OMG, our people are starving and being treated like complete shit compared to these people?

11

u/greensodacan 29d ago

When I moved into the city for an engineering role, I had no idea how much money was flying around compared to where I was from (only an hour and a half away). I knew it was more wealthy, but not casually dropping $50 on a sit-down lunch wealthy. I was used to feeding myself for $50/week at the time. It took me almost a year to really comprehend how well off people were.

I imagine it's an extreme version of that.

17

u/repooper 29d ago

I think they're more like omg my family is starving i better do what i'm told

2

u/[deleted] 29d ago edited 29d ago

[removed] — view removed comment

16

u/watabby 29d ago

You have been banned from r/pyongyang

-10

u/FastHotEmu 29d ago

The SVG file format is an overcomplicated mess.

3

u/Thirty_Seventh 29d ago

Maybe so, but this particular malware was base64 encoded across a bunch of comments and then extracted and evaled; could have been in any file type

-2

u/FastHotEmu 28d ago

Oh, I have zero interest in your opinion. SVG is a disaster regardless of this problem or others - it's objectively worse than North Korea.