Blockchain dev's wallet emptied in "job interview" using NPM package
bleepingcomputer.com
bleepingcomputer.com
A take-home for a web3 dev-job that pays less than California's minimum wage (as of April 2024) is a story in itself.
Is something blindly connecting to port 5000 and sending a secret payload without verifying what's connected on the other end? That seems like a recipe for chaos.
Maybe I'm misunderstanding your question though, can you clarify?
I had guessed that perhaps it's intercepting port 5000 and something else like Metamask was connecting to 5000 assuming something more innocuous was running on it, then forwarding that information? But like I said not sure without seeing the code.
Whole raison d’etre of IPv6 is to enable that.
The writing here, and the subject of the writing, has me convinced that people in "web 3" have no clue what they are doing.
The victim here seems to be _very_ confused about how this could have happened until others clarify it for them. Like, you downloaded and ran someone else's code - of course it has a reverse shell in it. Why aren't you capable of reading JS well enough to see that? Surely it wasn't that well obfuscated? And even if it was, why is it so confusing?
Saved you the click.