Frank Wiles discovered a sophisticated phishing attack where a fake project inquiry was used to trick him into cloning a malicious git repository. The repo contained a crafted post-checkout hook that would download and execute a remote binary using Vercel as command-and-control infrastructure, likely aiming to steal credentials.
Background
Git post-checkout hooks are rarely used in practice but can be weaponized to execute arbitrary code whenever a branch is checked out. This attack exemplifies the growing trend of supply-chain-style social engineering targeting developers through fake collaboration opportunities.
- Source
- Lobsters
- Published
- Oct 3, 2026 at 06:19 AM
- Score
- 7.0 / 10