Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Malicious repository

Giovanni Effio
January 23, 2026

This is a malicious repository: https://bitbucket.org/lmng-world/teddybear_pds/src/main/

It's part of a crypto recruiter scam. They give you a "technical assessment task" and send you this repo, which includes a .vscode/tasks.json file that automatically runs some shell commands upon opening it in VS Code. This downloads some malware which they use to open a backdoor into your system in an attempt to get your wallets' private keys and drain them.

This specific one contacted me through LinkedIn, leading me on as a supposed interview process. There were several red flags, so I knew it was a scam before getting access to the code ("co-founder" doing the intro call, very odd accent for the company's supposed base location, some other things)

Stay safe out there.

0 answers

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events