Fake Recruiters & Coding Tests

    The Assessment Is the Attack

    Fake recruiters ask developers to clone and run a project. Verify the recruiter and isolate any assessment.

    Developer & Technical SecurityDevelopersHR & recruitment

    Illustrative scenario

    How It Looks in Real Life

    A recruiter offers a well-paid remote role and sends a repository for a “take-home task”, asking you to run the install command and start the app before the interview.

    Understand it

    How the Attack Works

    The project contains code that runs during install or start-up and steals browser data, credentials, wallets or tokens. Microsoft and GitHub have both described campaigns targeting developers through fake interviews.

    Red flags

    Warning Signs

    • Recruiters you cannot verify through the company’s official site or staff.
    • Pressure to run the project on your current machine before any interview.
    • Obfuscated scripts, unexpected postinstall steps or binary files in the repo.

    Safer habits

    What to Do Instead

    • 1Verify the recruiter through the company’s official careers page or a known employee.
    • 2Run assessments only in a disposable VM or container without work credentials, SSH keys or wallets.
    • 3Read package scripts and install hooks before running anything.

    Response playbook

    Already Interacted?

    For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.

    If you: installed software or ran a command
    1. 1Disconnect the device from the network (Wi-Fi off or cable out) but leave it powered on.
    2. 2Report to IT or security and describe exactly what you ran or installed.
    3. 3Do not delete files, wipe the device or run cleanup tools yourself; evidence helps the investigation.
    4. 4From a different, trusted device, change passwords for accounts used on the affected machine.
    If you: exposed a token, key or secret
    1. 1Revoke or rotate the exposed secret at the provider first; deleting the commit or message is not enough.
    2. 2Report it to the security team with where and when it was exposed. Never paste the secret itself into the report.
    3. 3Review provider logs for use of the key after the exposure time.

    Knowledge Check

    What Would You Do?

    A recruiter sends a repo and asks you to run it on your work laptop “to save time”. Best response?

    Fictional example for learning. Not a test score or certification.

    Sources

    Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.

    All Awareness Guides

    Make Safe Habits Part of Your Culture

    Plain-language awareness sessions for everyday staff, developers and business teams.

    Email Us