r/webdev 🛠 Dev 👁 0

Heads up: fake "clients" on Dribbble/Upwork are sending GitHub repos that malware your machine on `npm install`

Got a normal-looking $3.5k website brief, articulate reply, then "review our current version before the call", then linked repo was a crypto dApp full of junk files and a committed `.env`. It's the Contagious Interview /

📄

This source provides headlines only. Use the button below to read the complete article on the original site.

📰 Read the original article on r/webdev

Originally published by r/webdev. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.