Skip to content

BuildNot yet confirmed elsewhere1 publisher2 min readPublished

Fake Taiko recruiter asks developers to paste its trojan into their own terminal

A fake recruiter impersonating Ethereum rollup company Taiko kept serving its job-offer trojan four days after a developer reported it to AWS. It ends the hiring flow by asking the candidate to paste a command into their terminal, a step no legitimate hiring process requires.

The Engineer · Build desk

How we use AISend a correction

What happened

  • The sending domain, taikotalent.xyz, was registered on September 27, eight days before the recruiting email arrived, according to the RDAP records the developer checked.
  • Taiko's real domain is taiko.xyz and its hiring runs through careers@taiko.xyz; the look-alike domain appears nowhere on the company's actual site.
  • The message passed SPF and both DKIM signatures, Resend's and Amazon's, after being relayed through Amazon SES in the sa-east-1 region.
  • The campaign goes after developers with public GitHub profiles, opening with 'I came across your GitHub profile' and collecting the recipient's name, email and GitHub username.
  • The pasted command double-forks to detach from the terminal, runs curl with TLS verification disabled, and sends all output to /dev/null, with a hidden-window variant for Windows.

Why it matters

  • constraint SPF and DKIM passing only shows the sender controls the domain, not that the mail is honest, so a filter that scores an authentication pass as safe delivers this to the inbox.
  • exposure Pasting the command runs a downloader that executes code on the developer's own machine, with whatever access that machine already carries.
  • decision Reporting it to the upstream providers had not pulled the payload, so a team's working defense now is the warning it gives its own people while any takedown is pending.
  • precedent The developer argues the brand is incidental and the terminal-paste pattern is what people fall for, so the same funnel should be expected under other employers' names.

Before the terminal step the campaign runs a short funnel. The emailed link opens a "Private invitation" single-page app gated by a per-recipient Ref code, and every interaction on it posts to a /track-activity endpoint that exfiltrates a device fingerprint of browser, screen and timezone [10].

The file the command fetches is a 49,916-byte Bash script that calls itself deepfake_guard [1]. The developer downloaded it to read, not to run [16]. Read statically, it relaunches itself detached with nohup, reports "install success" to a command-and-control endpoint at api.gaganata.ink with a fallback at api.fallgganata.ink, then decodes an embedded base64 second stage into /var/tmp/.kdm.XXXXXX and runs it with those addresses passed in as environment variables; the second stage holds the actual payload [2]. The script then deletes its own launcher, status file and temporary artifacts, retrying the cleanup up to 60 times [3].

On October 9 the file being served was byte-for-byte the sample the developer quarantined on October 5, SHA-256 c7c22e322c17bda8198257342d4034af6250a5c433242461b870879ba9aa285d [13]. He had reported the campaign on October 5 to AWS Trust and Safety under case P01M4696RCMDN90PYQGW7NJHGT0, to Resend's abuse address, and to Taiko's own careers address, where he recommended the company warn its applicants [14]. A day later he published a 17-page forensic writeup with indicators of compromise and full headers [17].

There is one rule that stops all of it, and the developer put it in the writeup: "A job application does not need your terminal. A job application has never needed your terminal." [12]

What to watch

  • Whether AWS, Resend or Taiko removes the taikotalent.xyz payload, and how long a takedown takes.
  • Whether Taiko posts the public warning to applicants the developer requested.
  • Whether the same terminal-paste funnel reappears under a different company's name.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The downloaded verify_m file is a 49,916-byte Bash stager that calls itself deepfake_guard.

  2. [2]

    The stager re-launches itself detached via nohup, reports 'install success' to a command-and-control endpoint at https://api.gaganata.ink/guard-launcher-result with a fallback at https://api.fallgganata.ink, and decodes an embedded base64 second stage to /var/tmp/.kdm.XXXXXX, executing it with the C2 endpoints exported as environment variables; the second stage is where the actual payload lives.

  3. [3]

    The stager deletes itself, including launcher, status file and the /var/tmp artifacts, in an anti-forensics loop that retries 60 times.

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 8, 2026

    A fake recruiter sent me a job offer that ended in my terminal — the trojan is still live

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories