最新报道:According to the V2EX website on July 28, user evada recently posted that during the application process, he was asked to use the GitHub project template development page specified by the recruiter, and found that the project contained malicious code. Specifically, the logo.png file in the project is an image on the surface, but it actually contains executable code and is triggered by the config-overrides.js file, with the intention of stealing the user's local cryptocurrency private key. evada pointed out that the malicious code will send a request to a specific URL, download the Trojan file and set it to start automatically at boot, which is extremely hidden and harmful. V2EX administrator Livid said that the account involved has been banned and GitHub has deleted the relevant malicious repository. Many users commented that this new type of scam targeting programmers is very confusing, reminding developers to be vigilant when running projects of unknown origin.