Developer hiring workflows can now deliver malware through projects that still appear to work. The trap is not the code review alone. Ordinary-looking SVG assets inside a take-home repo can hide the payload until the project is run, which means a legit test can steal browser sessions, crypto wallets, clipboard data, and files before anyone sees a broken build.
The campaign uses a fake job lure in Slack, then a trojanized repository with four stages tied to OtterCookie. The repository stays functional, but hidden data inside SVG flag images is assembled by code in the repo and can trigger on server boot; the payload also includes a Socket.IO backdoor. This turns candidate coding tests and shared developer workstations into a delivery path for both credential theft and downstream supply-chain access.
The new risk is the artifact itself. Teams that only inspect source logic can miss malware buried in image assets and other files that look harmless in a hiring exercise.