live · scanning repos
Scanrepo

Known Scams ░▒▓

Threat intelligence database. Lazarus Group / DPRK campaigns targeting developers.

17 accounts · 30 repos · 34 profiles

Scammer GitHub Accounts

Fake LinkedIn Recruiters

identities stolen by scammers — the real people are not responsible.

Malicious Repositories

Fake Interview Platforms

impersonating Willo and others to install malware as "camera drivers".

willointerview.comwilloassess.netwilloassess.comwilloassessment.comwillohiring.comwillotalent.prowillotalents.orgwillotalantes.comwillorecruit.comwillocandidate.comwillo-interview.uswillohiringtalent.orgwtalents.uscrypto-assessment.comblockchain-assess.comhiringinterview.orghiringtalent.prointerviewnest.orgvideoscreening.orgfundcandidates.comvideohirepro.com

C2 / Exfiltration Domains

command-and-control servers where stolen data is sent.

npoint.iopastebin.comrequestbin.netwebhook.sitepipedream.nethookbin.comw3capi.marketingmglcoin.ioflickthebean.onrender.comnvidia-release.orgnvidia-release.uscamera-drive.cloudnvidia-drive.cloudjz-aws.infochainlink-api-v3.comip-api-test.vercel.appvscode-config-settings.vercel.appvscode-load-two.vercel.appvscode-settings-bootstrap.vercel.appvscodesettingtask.vercel.appapi-web3-auth.vercel.appcoredeal2.vercel.app

How the Scam Works░▒▓

1Recruiter contacts you on LinkedInFake recruiter with attractive crypto/Web3 job. Profile looks legit. Sometimes deepfake video — ask them to blink.
2Sends a "technical assessment"GitHub/Bitbucket repo to complete. Uses Google Docs or Notion pages to appear legitimate.
3Victim runs npm installMalicious preinstall/postinstall scripts, poisoned configs, or .vscode/tasks.json that auto-runs on folder open.
4BeaverTail + InvisibleFerretBeaverTail steals browser creds & wallets. InvisibleFerret installs persistent backdoor. Attribution: Lazarus Group / DPRK.
attribution & sources

Lazarus Group / BlueNoroff / APT38 (DPRK state-sponsored). Campaigns: Contagious Interview, Dangerous Password. Connected to billion-dollar crypto thefts.

Report a Scam

found a malicious repo or scammer? contribute to the open-source database.

contribute ↗