I got targeted: Trying to get your credentials via a git post-checkout hook
In an attempt to gain unauthorized access to my laptop, I was targeted by someone who sought to run arbitrary code on my system. The attack began with a seemingly legitimate project inquiry, which requested a meeting to discuss a web application project in the EdTech space. I mentioned that I usually follow up on such projects and offered to set up a call via Calendly. The potential client then asked me to review the project details before the meeting and sign an NDA.
Initially, I didn't notice the hidden .git folder in the Dropbox link. It was only when I couldn't locate the NDA or NDA template that I reached out to the client for the document. Upon investigation, I discovered that they had placed all the *.example hooks in the .git/hooks folder, along with one genuine post-checkout hook. Intrigued by the contents of the post-checkout hook, I opened it, revealing a nefarious plan to download an OS-specific binary, make it executable, run it, and then delete it.
I promptly reported the matter to Dropbox and Vercel's security teams, hoping to neutralize the threat before they could reach any unsuspecting targets. The perpetrator had also impersonated a development shop owner, further exploiting the victim's trust. While I managed to thwart this particular attempt, it serves as a reminder for others to remain vigilant and safeguard their credentials with utmost care, as cybercriminals are becoming increasingly cunning and determined to infiltrate systems.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.