Switch language한국어
Back to the list

A LinkedIn job offer promised remote work and video games: it was a triple trap designed by North Korean hackers

TL;DR AI

Key summary

2 min read
  1. North Korea-linked hackers lured developers with fake remote job offers on LinkedIn that hid malware inside a GitHub repository.

  2. The campaign matched cases involving a Spanish blockchain developer and another security executive, and has been attributed to the Lazarus Group.

  3. The malicious project used multiple infection paths, including VS Code task execution and npm-based credential theft, to compromise victim systems.

  4. The operation shows how hiring platforms are being abused to steal credentials, take over developer machines, and infiltrate crypto and software environments.

Read the original