
A backdoor hidden in a LinkedIn job offer: how a fake recruiter trapped a developer
A full-stack developer asked to review a GitHub repository for a job opening found a hidden backdoor that runs on npm install. The repository's commits and the recruiter's profile belonged to two real people who had never worked on the project.
In early June 2026, full-stack developer Roman Imankulov received a LinkedIn message from a "recruiter" at a small crypto startup. After a few days of exchanging messages, she described a broken proof-of-concept that needed a lead engineer and sent him a public GitHub repository to review — specifically asking him to "check out the deprecated Node modules issue". Reviewing an existing codebase is not unusual, but something felt off, so he decided to be extra careful.
Instead of cloning the repo and installing dependencies on his own machine, he spun up a throwaway VPS on Hetzner, cloned the repository there and pointed an AI agent, Pi, at it in read-only mode with only file-reading tools enabled: read, grep, find and ls.
The trap inside a test file
The agent stopped almost immediately at app/test/index.js. The repository looked like a React frontend with a Node backend, and the trap was about 250 lines disguised as a test suite. Inside, a URL was assembled from fragments — protocol "https", domain "store", subdomain "rest-icon-handler", path "/icons/" and token "77".
On line 225, buried between walls of commented-out tests, the payload ran anything the server sent back to the machine. The file did not wait for tests to run: app/index.js executes require('./test'), and package.json wires app/index.js into startup through the prepare script. npm runs prepare automatically after npm install, so simply installing dependencies executed the backdoor. The instruction about "deprecated Node modules" was bait.
A borrowed identity, twice over
The repository's 39 commits were authored under the name and email of a real developer — a full-stack engineer with an ordinary LinkedIn profile, a personal website and a long GitHub history. Imankulov messaged him and learned he had never worked for the company and had nothing to do with the repository; he had been impersonated on GitHub before and had a repo taken down over it.
The recruiter's profile was borrowed as well: it belonged to a well-known arts journalist with a long cultural background and nothing technical in it. When Imankulov said he could not get the project to install, the journalist instantly turned into an expert on npm and Node versions, pushing him to run npm install.
Why it matters
Imankulov writes that he had heard about such attacks before, but when one came after him it still caught him off guard; on a more tired or rushed day, he could easily have run npm install before thinking it through. He reported the repo to GitHub and the recruiter to LinkedIn. So far nothing has changed and the code is still up.
There is a second, more technical takeaway: reviewing the code with a read-only agent turned out more productive than reading it himself. The backdoor was dressed up as sloppy beginner code, but the agent flagged it in seconds. The practical rule is simple — open unknown repositories in an isolated environment and install nothing until the code has been read.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.