Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More

Owned by Manuel

AI Dojo: code RL in games

4 members • $5/month

Learn to train AI for SpaceInvaders and other games. We use Godot, a very beginner friendly engine with Python-like coding. (RL/ML, no ChatGPT)

Memberships

Clief Notes

43.6k members • Free

Skoolers

161.5k members • Free

Synthesizer: Free Skool Growth

45.1k members • Free

GOOSIFY: Skool Made Fun

13.1k members • Free

Skool Gameplan

2.2k members • Free

Robotics and Automation

127 members • Free

AI Robotics School🔥

310 members • Free

AI Automation (A-Z)

164.9k members • $7/month

🇦🇹 Vienna IRL

112 members • Free

1 contribution to Clief Notes
I was (likely) targeted by North Korean hackers, so I found the payload and reverse-engineered a security tool.
A recruiter contacted me on LinkedIn on Wednesday. CEO of a crypto startup, $125/hr advisory role, review our product via GitHub repo as the first interview step. The social engineering was top-notch, polished profile with 500+ connections, days of back and forth DMs, the cracks only appeared in hindsight. Friday, I got access to the repo, which felt like a win. With a healthy amount of skepticism, I reviewed the repo with Claude. The codebase looked professional and complete, the README was well structured, and the .json files where malware would normally be hidden came back clean. The payload was buried well enough that Claude and I missed it. Luckily, I decided to enjoy my Friday night and not clone the repo. This is the main reason I want to share my story here: many of us are starting new businesses, and when someone offers you a paid role that seems like the perfect fit, your judgment becomes clouded. I know mine did.Having had more time to think, the inconsistencies started to surface. Lying in bed around midnight on Saturday, the eureka moment happened. This was definitely an elaborate scam. I stayed up all night digging through the repo and gathering evidence to file reports. Here’s what I found: The repo contained a fully operational malware delivery chain: - .vscode/tasks.json configured with runOn: folderOpen — silent code execution the moment you open the folder in VS Code, zero prompt. - .githooks/post-checkout buried under 40 lines of decoy comments, downloading and executing a remote payload from a Vercel server across Mac, Linux, and Windows simultaneously, all output suppressed. - Private key social engineering via the .env.local README instruction, a backup vector in case the malware delivery fails or gets caught  - This is a complex attack chain designed to pass pre-clone inspection. Once you clone it, you’re cooked. I stayed up all night gathering evidence and filing reports: Vercel - both domains, GitHub - account + repo, LinkedIn profile, Basescan wallet flagged, Neynar/Farcaster. Then the big guns: RCMP/CAFC and FBI IC3. But then I started thinking, what tools should I have used to protect myself in this situation?
I was (likely) targeted by North Korean hackers, so I found the payload and reverse-engineered a security tool.
2 likes • May 19
wow, thanks for the warning and insights
1-1 of 1
Manuel Karner
1
3 points to level up
@manuel-karner-6479
AI Engineer, building LLM pipelines but lately really into RL for games. Started this to go deeper and bring others along.

Active 2h ago
Joined May 19, 2026
INFJ
Powered by