A backdoor in a LinkedIn job offer
2026-06-15 • Roman •
A developer-targeted LinkedIn recruiting lure sent the author to a public GitHub repository containing a hidden Node.js backdoor. The malicious code in `app/test/index.js` assembled `https://rest-icon-handler.store/icons/77` and was designed to execute whatever the remote server returned, while `package.json` used an npm `prepare` lifecycle script so `npm install` would trigger it automatically. The operation also used borrowed identities: commits were attributed to a real developer who denied involvement, and the recruiter profile appeared to impersonate a real non-technical journalist.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | rest-icon-handler.store | 2026-06-15 | 2026-06-15 |
| URL | https://rest-icon-handler.store… | 2026-06-15 | 2026-06-15 |
Related Reports
2026-06-30 •
46% Match
#Cryptocurrency
#GitHub
#NPM
#ContagiousInterview
#VSCode
#T1041
#T1071.001
#T1059.007
#T1027
#T1204
#T1059.001
#T1105
Shares tags: GitHub, NPM • Published within a month
Shares tags: Phishing, NPM • Published within a week
2026-06-08 •
46% Match
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency
Proofpoint
Shares tags: Phishing, GitHub • Published within a week
2026-05-28 •
46% Match
#Phishing
#macOS
#NPM
#T1041
#T1195.002
#T1204.002
#T1555.003
#T1539
#T1552.001
#JINX-0164
Shares tags: Phishing, NPM • Published within a month
Shares tags: GitHub, NPM • Published within a month
Shares tags: Phishing, GitHub