1/6 🚨 SECURITY ALERT: LinkedIn Fake Recruiter Malware Campaign 🚨
Got hit (again) with a sophisticated malware delivery attempt via LinkedIn today. Sharing so nobody becomes exhibit B.
The (usual) Attack Flow
1. Initial Contact: Fake recruiter "Anzhelika Anpolska" (
linkedin.com/in/anzhelika-an…) - profile looks legit enough to pass a 5-second glance
2. Social Engineering: Standard recruitment playbook with artificial urgency (because top talent is definitely recruited via cold LinkedIn DMs asking you to run
random code)
3. Malicious Repository:
bitbucket.org/datalake-organ…
4. The Trap: "Please review this code" - except it's heavily obfuscated JavaScript that no legitimate company would ever send
The Payload
Found the malicious code in ps.config.js - and by "found" I mean "immediately recognized because legitimate code doesn't look like this."
Technical Analysis: