A developer received a suspicious job offer with a high salary and a take-home interview project, which turned out to be a malware-laced assignment. The project contained a hidden directory with a Git hook that executed a remote payload when a Git command was run. The payload installed Node.js and other dependencies, and attempted to interact with the user's system. The developer investigated the attack and found that it was a widespread campaign using a cloned public repository.