The Coding Challenge That Was the Attack
| 35 min read
For Developers A July 2026 campaign recruited developers through Slack, then delivered four-stage malware inside a trojanised e-commerce repository presented as an interview exercise. The payload hid in an SVG and no antivirus flagged it. Running a stranger's repo is executing their code.