{
  "id": 11542186,
  "title": "I got targeted: Trying to get your credentials via a git post-checkout hook",
  "url": "https://urgent.news/2026/10/02/i-got-targeted-trying-to-get-your-credentials-via-a-git-post-checkout",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-02T22:19:02.000Z",
  "source": {
    "name": "Lobsters",
    "slug": "lobsters",
    "url": "https://frankwiles.com/posts/i-got-targeted/"
  },
  "original_language": "en",
  "account": "In an attempt to gain unauthorized access to my laptop, I was targeted by someone who sought to run arbitrary code on my system. The attack began with a seemingly legitimate project inquiry, which requested a meeting to discuss a web application project in the EdTech space. I mentioned that I usually follow up on such projects and offered to set up a call via Calendly. The potential client then asked me to review the project details before the meeting and sign an NDA.\n\nInitially, I didn't notice the hidden .git folder in the Dropbox link. It was only when I couldn't locate the NDA or NDA template that I reached out to the client for the document. Upon investigation, I discovered that they had placed all the *.example hooks in the .git/hooks folder, along with one genuine post-checkout hook. Intrigued by the contents of the post-checkout hook, I opened it, revealing a nefarious plan to download an OS-specific binary, make it executable, run it, and then delete it.\n\nI promptly reported the matter to Dropbox and Vercel's security teams, hoping to neutralize the threat before they could reach any unsuspecting targets. The perpetrator had also impersonated a development shop owner, further exploiting the victim's trust. While I managed to thwart this particular attempt, it serves as a reminder for others to remain vigilant and safeguard their credentials with utmost care, as cybercriminals are becoming increasingly cunning and determined to infiltrate systems.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}