TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Tell HN: Be cautious with take-home challenges

5 点作者 AlexITC超过 1 年前
Hi hn,<p>As devs, we got used to take-home challenges while applying for jobs&#x2F;projects, some challenges ask you to write code from scratch, others expect you to update an existing project.<p>Today I had a case where I received a repository where I was asked to do a minor change before discussing the long-term opportunity.<p>Well, turns out that the build script links a weird pre-start script, paying attention to this I found out that the script was malicious.<p>One of the things that made me suspicious was the lack of details from the hiring company + getting the take-home challenge without much effort.<p>All of this got me thinking, there is nothing preventing attackers to create a fake company website&#x2F;jobs&#x2F;emails and leverage the take-home challenge approach to infect people.<p>Have you saw any similar approach?

1 comment

not_your_vase超过 1 年前
I definitely remember reading about similar cases on HN some time ago: random HR tries to poach a dev from a company, but during the interview they manage to hack the current employer of the dev. Maybe I can even find it... (though don&#x27;t hold your breath)<p>Edit: If you were holding your breath, you can let it go: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=32001742">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=32001742</a>
评论 #37314515 未加载