BuildNot yet confirmed elsewhere1 publisher2 min readPublished
Fake Taiko recruiter asks developers to paste its trojan into their own terminal
A fake recruiter impersonating Ethereum rollup company Taiko kept serving its job-offer trojan four days after a developer reported it to AWS. It ends the hiring flow by asking the candidate to paste a command into their terminal, a step no legitimate hiring process requires.
The Engineer · Build desk
What happened
- The sending domain, taikotalent.xyz, was registered on September 27, eight days before the recruiting email arrived, according to the RDAP records the developer checked.
- Taiko's real domain is taiko.xyz and its hiring runs through careers@taiko.xyz; the look-alike domain appears nowhere on the company's actual site.
- The message passed SPF and both DKIM signatures, Resend's and Amazon's, after being relayed through Amazon SES in the sa-east-1 region.
- The campaign goes after developers with public GitHub profiles, opening with 'I came across your GitHub profile' and collecting the recipient's name, email and GitHub username.
- The pasted command double-forks to detach from the terminal, runs curl with TLS verification disabled, and sends all output to /dev/null, with a hidden-window variant for Windows.
Why it matters
- constraint SPF and DKIM passing only shows the sender controls the domain, not that the mail is honest, so a filter that scores an authentication pass as safe delivers this to the inbox.
- exposure Pasting the command runs a downloader that executes code on the developer's own machine, with whatever access that machine already carries.
- decision Reporting it to the upstream providers had not pulled the payload, so a team's working defense now is the warning it gives its own people while any takedown is pending.
- precedent The developer argues the brand is incidental and the terminal-paste pattern is what people fall for, so the same funnel should be expected under other employers' names.
Before the terminal step the campaign runs a short funnel. The emailed link opens a "Private invitation" single-page app gated by a per-recipient Ref code, and every interaction on it posts to a /track-activity endpoint that exfiltrates a device fingerprint of browser, screen and timezone [10].
The file the command fetches is a 49,916-byte Bash script that calls itself deepfake_guard [1]. The developer downloaded it to read, not to run [16]. Read statically, it relaunches itself detached with nohup, reports "install success" to a command-and-control endpoint at api.gaganata.ink with a fallback at api.fallgganata.ink, then decodes an embedded base64 second stage into /var/tmp/.kdm.XXXXXX and runs it with those addresses passed in as environment variables; the second stage holds the actual payload [2]. The script then deletes its own launcher, status file and temporary artifacts, retrying the cleanup up to 60 times [3].
On October 9 the file being served was byte-for-byte the sample the developer quarantined on October 5, SHA-256 c7c22e322c17bda8198257342d4034af6250a5c433242461b870879ba9aa285d [13]. He had reported the campaign on October 5 to AWS Trust and Safety under case P01M4696RCMDN90PYQGW7NJHGT0, to Resend's abuse address, and to Taiko's own careers address, where he recommended the company warn its applicants [14]. A day later he published a 17-page forensic writeup with indicators of compromise and full headers [17].
There is one rule that stops all of it, and the developer put it in the writeup: "A job application does not need your terminal. A job application has never needed your terminal." [12]
What to watch
- Whether AWS, Resend or Taiko removes the taikotalent.xyz payload, and how long a takedown takes.
- Whether Taiko posts the public warning to applicants the developer requested.
- Whether the same terminal-paste funnel reappears under a different company's name.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The downloaded verify_m file is a 49,916-byte Bash stager that calls itself deepfake_guard.
- [2]
The stager re-launches itself detached via nohup, reports 'install success' to a command-and-control endpoint at https://api.gaganata.ink/guard-launcher-result with a fallback at https://api.fallgganata.ink, and decodes an embedded base64 second stage to /var/tmp/.kdm.XXXXXX, executing it with the C2 endpoints exported as environment variables; the second stage is where the actual payload lives.
- [3]
The stager deletes itself, including launcher, status file and the /var/tmp artifacts, in an anti-forensics loop that retries 60 times.
- [4]
On October 5, 2026 the developer received a recruiting email that ended with a step he says no legitimate hiring process has ever asked for: opening the terminal and pasting a command to 'verify I'm not a bot.'
- [5]
The email claimed to be from 'Joseph Quintana, Talent' at Taiko, the Ethereum rollup company, offering a Software Engineer role on based-rollup, ZK proving and L2 systems; the sending address was josephquintana@hr.taikotalent.xyz.
- [6]
Taiko's real domain is taiko.xyz and its real recruiting runs through careers@taiko.xyz; there is no reference to taikotalent.xyz anywhere on the real site.
- [7]
taikotalent.xyz was registered on 2026-09-27, eight days before the email arrived, per RDAP.
- [8]
The email was sent through Resend and relayed through Amazon SES in sa-east-1; SPF passed and DKIM passed twice, once for Resend's signature and once for amazonses.com. The developer notes authentication passes only prove the sender controls an eight-day-old domain and say nothing about intent.
- [9]
The campaign targets people with public GitHub profiles; the email opens with 'I came across your GitHub profile,' and the form collects full name, email and GitHub username.
- [10]
The link goes to a 'Private invitation' single-page app gated by per-recipient Ref codes; every step of the form posts to /track-activity, which exfiltrates a deviceInfo fingerprint of browser, screen and timezone on every interaction.
- [11]
The macOS/Linux command uses a perl double-fork to detach the process from the terminal so it survives the window closing, curl -ks to disable TLS certificate verification, and &>/dev/null& to silence all output; the Windows version runs the downloader in a hidden window with start -WindowStyle Hidden.
- [12]
A job application does not need your terminal. A job application has never needed your terminal.
- [13]
On October 9, 2026 the payload being served was byte-identical to the one quarantined on October 5, SHA-256 c7c22e322c17bda8198257342d4034af6250a5c433242461b870879ba9aa285d.
- [14]
On October 5 the developer sent a full report to AWS Trust & Safety under case P01M4696RCMDN90PYQGW7NJHGT0 / 179121234700301, to abuse@resend.com, and to careers@taiko.xyz, recommending a public warning from Taiko.
- [15]
Four days after the developer reported it to AWS, the trojan was still being served, as of October 9, 2026.
- [16]
The developer downloaded verify_m for analysis and never executed it; the methodology throughout was non-destructive, consisting of fetch, hash and read.
- [17]
On October 6 the developer generated a 17-page forensic report including indicators of compromise and full headers.
- [18]
The social-engineering pattern -- a job application that ends in Terminal -- is the part your coworkers, your juniors and your family will fall for.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toA fake recruiter sent me a job offer that ended in my terminal — the trojan is still live
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Email Authentication (DKIM/DMARC)Follow
- Attacks on developersFollow
- Fake-recruiter malware campaignsFollow