Comment by lebed2045
1 month ago
Revenge! A friend of mine was scammed this way two years ago.
So when I finally received a similar offer on LinkedIn, I made them pay to me, twice XD
They sent me a GitHub repository and claimed they needed help deploying a token or something similar. The obvious goal was to get me to run their code while connected to a wallet with real funds.
I told them: sure, I can probably help, but my time costs money.
So I convinced them to pay me for a consultation. For half an hour, I explained how “amazing and simple” the process was, and how they could do it themselves. They claimed to be from the US, but on the call they had an extremely heavy Asian accent. I even recorded part of it on camera, because the whole situation was ridiculous.
Before they could get too furious, I told them I did not have more time and that they would need to book another call. So they paid me a second time.
Before the second call, i got myself absolutely new macbook was for fun testing it, basically a fresh Mac (i should have been using vm because it’s faster to restore but that time i wasn’t familiar with UTM and i got parallels which is scam itself), just to see how their scam worked.
The scam was classic npm install-style: get someone to run scripts from a Git repo and hope they are unaware of how much access that can give to their machine.
Honestly, two years ago, I also did not fully understand that simple ‘nom install’ could give attackers such deep access to your computer.
No comments yet
Contribute on Hacker News ↗