exploit by job interview
2023-12-29 23:29:31.387186+01 by Dan Lyke 1 comments
Bleeping Computer: Blockchain dev's wallet emptied in "job interview" using npm package
As a part of the job interview, the recruiter asked Çeliktepe to download and debug the code in two npm packages—"web3_nextjs" and "web3_nextjs_backend" hosted on a GitHub repository. However, moments later, the developer discovered that his MetaMask wallet had been drained—with upwards of $500 siphoned out of his account, based on the information seen by BleepingComputer.