Back
Fake project repo hid a git hook that targeted a developer's credentials
SiTech AI Team3 min read

Fake project repo hid a git hook that targeted a developer's credentials

Frank Wiles, founder of REVSYS and a member of the Django Steering Council, was targeted with a fake project repo whose hidden git post-checkout hook was designed to run malware on his laptop. He spotted it in time.

A fake client and a hidden .git directory

Frank Wiles, founder of the development firm REVSYS, a member of the Django Steering Council and a former president of the Django Software Foundation, has published an account of a targeted attack against him. In a post dated 2 October 2026, he describes how an ordinary-looking project inquiry turned out to be an attempt to run arbitrary code on his laptop, apparently to gain access to his GitHub account and the client systems he can reach through his firm.

The inquiry looked like normal business: someone asked whether his team was available to build a web app in the Ed Tech space. Wiles offered to set up a call. The prospect asked him to read a project overview and sign an NDA before the meeting, then shared a Dropbox folder with several folders of Markdown files. The spec was vague, but detailed enough to pass as a real minimum viable product.

Wiles initially missed the .git directory hidden among those files.

“Switch to the NDA branch”

When he could not find an NDA, the client said it was kept in the NDA branch and told him to switch to it, fill it in and return it before their meeting. That is when Wiles realized the project was not real. He opened the .git/hooks folder and found all of the standard example hooks alongside a single real post-checkout hook.

No one normally uses those, so he opened it carefully. The hook used a Vercel app as its command-and-control channel: it downloaded an OS-specific binary, made it executable, ran it and then deleted itself. Because git runs a post-checkout hook automatically whenever a branch is checked out, simply following the instruction to switch branches would have executed the payload with the developer’s own permissions.

Wiles alerted Dropbox and Vercel security teams immediately so the accounts could be taken down before they caught someone else. He also noted that the attackers were impersonating an unsuspecting development shop owner as part of the ruse. Wiles himself was not compromised.

Why developers are a target

The scheme abuses a workflow developers rely on every day. Git hooks execute without confirmation, and a .git folder is easy to overlook in a shared archive. The potential payoff was significant: GitHub access, SSH keys, API tokens, CI secrets and reach into client systems.

Wiles’s advice is to be extra vigilant and to watch credentials closely. In practice that means treating unsolicited “dream projects” that push you toward repository operations with suspicion, inspecting hooks before running anything from an untrusted repo, and opening unfamiliar code only in a disposable, isolated environment.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.