Developer Frank Wiles wrote on October 2, 2026 that attackers tried to take over his accounts with a booby-trapped git repository. The trap was a post-checkout hook, a script that git runs every time you switch branches. It is the latest case in a campaign that has hit job seekers since at least May. For developers, the lesson is that simply checking out a branch in someone else's repository can run their code.
What happened to Frank Wiles
The attacker posed as the owner of a development shop, Wiles wrote on his blog. They asked him to review an NDA, a non-disclosure agreement, and shared a repository through Dropbox. Then they asked him to switch to an "NDA branch."
That branch switch was the trigger. A post-checkout hook sat in the repository's .git/hooks/ folder. When Wiles changed branches, the hook downloaded a program built for his operating system from a server hosted on Vercel. It made the file executable, ran it, then deleted itself.
Wiles believes the goal was to "gain access to my Github account and/or other REVSYS client related access." He notes that the post-checkout hook is rarely used, which makes it easy to miss. His advice to other developers is to be "extra vigilant and watch your credentials like a hawk."
How git hooks become a weapon
Git hooks are small scripts that git runs automatically at set moments, such as before a commit or after a checkout. They are a normal feature, used for tasks like running a linter. A normal git clone from a server does not copy hooks, which is why these attackers use other routes.
The reports show two routes:
-
Ship the whole folder. Wiles got his repository through Dropbox. In a case Andrii analyzed in a May blog post, the target received a "demo codebase" on Google Drive. A shared folder or archive can include the hidden
.gitdirectory, hooks and all. -
Ask the victim to turn hooks on. OpenSourceMalware describes repositories that keep hooks in a
.githooksfolder. Victims appear to have enabled them withgit config core.hooksPath .githookswithout reading them.
Either way, the hook runs during ordinary work. In the case Andrii analyzed, it fired on git checkout dev, the command to view the main code.
What the malware steals
The payloads differ, but they aim at the same things. Andrii's analysis found a program that looked for SSH keys such as id_ed25519, .env files, cryptocurrency wallets and certificates. It scanned the Desktop, Documents and Downloads folders and uploaded files under 10 MB. It also sent the clipboard's contents every second, and it let the attacker run commands on the machine.
A July write-up on the Citizen Dot blog describes a similar trap behind a fake job. A "recruiter" on LinkedIn offered a remote contract paying "$10,000-$15,000 a month." The take-home project came as a zip on Google Drive, with a git hook that pulled down a crypto-wallet stealer.
Who is behind it
OpenSourceMalware ties the campaign to the Lazarus Group, the North Korean hacking group. It links the git-hook trick to the "Contagious Interview" campaign of fake job interviews, which mostly targets people in crypto and web3. In the cases it studied, the malware ran "the first time the candidate tries to fix the bug and commit." It called post-checkout hooks an "even nastier" variant, because they fire on a simple branch change.
The case Wiles describes used a fake client and an NDA, not a job offer. The method, a hidden hook that downloads its payload from a server, is the same.
What this means for developers
Never open a repository you received as a folder or archive on your own machine. Clone it fresh from a git host instead, or open it inside a throwaway virtual machine or container. A fresh clone leaves the sender's hooks behind.
Before running any git command in shared code, look inside .git/hooks/ for files without the .sample ending. Check .git/config for a hooksPath setting, and look for a .githooks folder. The Citizen Dot author's advice is to inspect hidden folders like .git and .vscode before touching untrusted code.
You can also switch hooks off for a single command. Running git -c core.hooksPath=/dev/null checkout <branch> points git at an empty location, so no hook runs.
Treat any request to change your git settings as a red flag. A real client or employer has no reason to ask you to enable their hooks. If you think a hook already ran, assume your SSH keys, tokens and .env secrets are exposed. Rotate them from a clean machine, and check your GitHub account for new keys or sessions.
This article was first published on Tech AI Wire.
Also available in
Deutsch · 日本語 · Français · Español · Português
Sources
- I got targeted: Trying to get your credentials via a git post-checkout hook - Frank Wiles
- Be careful with your Git: Investigating malware spreading through Git repositories - andrii.ro
- Lazarus Group Uses Git Hooks To Hide Malware - OpenSourceMalware
- I Inspected My Take-Home Interview Project. It Was a Trap - Citizen Dot
Top comments (0)