Skip to content

Build1 publisher3 min readPublished

Trusting the repository author in VS Code runs the fake recruiter's task file

Microsoft's Defender Experts date the Contagious Interview campaign to December 2022. Its payload lands at the one hiring stage where a candidate is expected to clone and run a stranger's code. The same team tells employers to give staff a non-persistent VM for coding tests.

The Engineer · Build desk

What happened

  • One variant waits in Visual Studio Code: opening the downloaded package prompts the victim to trust the repository author, and that grant lets the editor run the repository's own task configuration file.
  • BBC World Service reported on 4 September 2026 that a UK job seeker who completed an assessment delivered in a Google Sheet had 18,000 pounds of cryptocurrency savings emptied within hours.
  • Microsoft's analysis lists what the operators collect: API tokens, cloud credentials, signing keys, cryptocurrency wallets and password manager artifacts.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure The risk lands on the candidate's current employer too: the assignment runs on a laptop that reaches source control, build pipelines and cloud consoles belonging to whoever currently employs the candidate.
  • constraint Standard advice to never run unknown code cannot be followed at the one hiring stage that requires running code, so the guidance has to be replaced with an environment.
  • precedent A candidate asking for a hosted environment before cloning anything becomes a routine request. Declining an assignment stops counting against them.

In Visual Studio Code, the dialog asking whether you trust the repository author is an execution decision. Microsoft's Defender Experts describe the variant plainly: when victims open the downloaded package in the editor, they are prompted to trust the repository author, and granting that trust lets the editor run the repository's own task configuration file [7].

The other two routes are more familiar. The main one tells the victim to clone and execute an NPM package hosted on GitHub, GitLab or Bitbucket [5]. The third puts a fabricated technical error on a fraudulent interview site and instructs the user to copy and paste a command to resolve it [6]. All three sit at the assignment, the only stage of hiring where running someone else's code is the task [1]; every other stage can be done with nothing but a browser and a camera [21].

Microsoft's team wrote on 11 March 2026 that the operation has been active since at least December 2022 [2], about 39 months of running time by the date of that writeup [18]. The UK loss BBC World Service reported came on 4 September 2026 [11], a little under six months after the Defender research went out [19].

That candidate handed in their notice, said so on LinkedIn, and took a call from a recruiter with a role for them. A video interview followed, then a standard technical assessment with the instructions sitting in a Google Sheet. Within hours of completing it, attackers emptied their cryptocurrency accounts of 18,000 pounds in savings, the BBC reported [11]. The pages in that case were real Google pages and the installer was digitally signed [12].

Microsoft's researchers named the pressure that makes the assignment work. Threat actors, they wrote, "exploit the trust job seekers place in the hiring process during periods of high motivation and time pressure, lowering suspicion and resistance" [8]. The same team wrote that "this campaign weaponizes hiring processes into a persistent attack channel" [9].

What the operators take is credentials. Per the Defender Experts analysis, they harvest API tokens, cloud credentials, signing keys, cryptocurrency wallets and password manager artifacts [10]. A developer laptop is a route into source control, build pipelines and cloud consoles, and the same laptop usually holds a password manager and often enough a wallet [20].

Employers already have this control. Microsoft tells them to give their own developers a non-persistent virtual machine for coding tests [13]. The dev.to write-up that assembled this record argues a candidate deserves the same boundary [14]. A team that mails out take-homes can provision that environment, or it can accept that the submission was produced on hardware it will never see. For the candidate, the same write-up is direct: no real employer needs you to execute unfamiliar code on your personal machine, and at a real employer, refusing carries no cost [15].

One number in the record measures the candidate pool. LinkedIn's data on what it calls the Gen Z "Scam Gap" found that younger professionals face the highest exposure to scams, and that 32% admit to ignoring red flags due to a competitive job market [16]. The write-up flags the limit itself: the survey covers how people behave under scarcity, and it does not count attacks [17].

What to watch

  • Whether any employer publishes a candidate-facing disposable environment for take-home assessments, and who pays for the instance hours.
  • Whether Defender Experts report the editor-trust variant moving beyond NPM packages into other package ecosystems.
  • Whether recruiters start being asked for a hosted assessment environment as a condition of doing the take-home at all.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories