A LinkedIn job offer promised remote work and video games: it was a triple trap designed by North Korean hackers

TL;DR AI
2 min readKey summary
North Korea-linked hackers lured developers with fake remote job offers on LinkedIn that hid malware inside a GitHub repository.
The campaign matched cases involving a Spanish blockchain developer and another security executive, and has been attributed to the Lazarus Group.
The malicious project used multiple infection paths, including VS Code task execution and npm-based credential theft, to compromise victim systems.
The operation shows how hiring platforms are being abused to steal credentials, take over developer machines, and infiltrate crypto and software environments.



