I Inspected My Take-Home Interview Project. It Was a Whole Operation

Dream job offer turns into a creepy trap, and commenters are equal parts horrified and impressed

TLDR: A fake-looking job interview assignment appears to have hidden a secret script meant to run on applicants’ computers. Commenters were split between horror and reluctant respect, with many warning that direct recruiter messages now deserve the same suspicion as scam phone calls.

What started as a too-good-to-be-true LinkedIn job pitch quickly turned into pure internet nightmare fuel. The writer says a recruiter offered eye-popping pay for a remote Python role, sent over a polished-looking take-home assignment, and everything seemed oddly legit — until a quick peek inside the hidden files revealed the real plot twist. Buried in the project was a booby-trapped setup that could secretly run code on the applicant’s computer. In plain English: this wasn’t just a test project, it looked like a trap.

And the Hacker News crowd absolutely pounced. The strongest reaction was a mix of alarm and grim admiration. One commenter basically said, “This is disgusting... but wow, they clearly know what they’re doing,” which is the most Hacker News way possible to describe a scam. Others turned practical fast, saying this is the job-search version of a fake bank call: if someone comes to you first, go verify the company yourself through its real website before touching anything.

Then, because the internet can never stay serious for long, the thread swerved into comedy. One person brought up a video of a scammer getting confused by a bizarre operating system. Another got jump-scared by the Harry Potter theme autoplaying on the author’s site and called it “bad UX,” which somehow became part of the vibe. The overall mood? People are rattled, not shocked. The scary consensus is that this kind of fake hiring stunt may only get more common.

Key Points

  • The author was approached on LinkedIn for a remote Python developer role offering $10,000-$15,000 per month on a contract-to-hire basis.
  • The recruiter quickly moved the author to a take-home assignment shared via Google Drive as a ZIP archive and PDF instructions.
  • The extracted assignment initially appeared legitimate, resembling a standard FastAPI and SQLAlchemy backend with no suspicious packages in requirements.txt.
  • A manual inspection of hidden files revealed a .git directory containing numerous preconfigured Git hooks.
  • The repository’s pre-commit hook was configured to detect the operating system and silently download and execute a remote payload from 45.61.164.38.

Hottest takes

"It's nasty, but I have to respect their skills" — ChrisMarshallNY
"When they reach out directly... assume malfeasance" — gtowey
"the harry potter theme song scared the shit out of me" — rdksu
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.