2026-10-11 17:10 UTC

Frank Wiles reports a targeted campaign delivered a Dropbox-shared .git folder whose malicious post-checkout hook used a Vercel app for command and control — downloading an OS-specific binary, executing it, and self-deleting — in an attempt to steal his developer credentials; more victims surfacing, or git platforms and security tooling explicitly countering checkout-time hook execution, would establish this as an established developer-supply-chain TTP with direct implications for agents cloning untrusted repositories.

state: seedheat: lowuncertainty: mediumknownscott: mediumgit-hooks developer-supply-chain credential-theft agent-sandboxingFrank WilesREVSYS

What is this?

Frank Wiles, an open-source consultant identified in the case with REVSYS, has published a first-person account of a targeted social-engineering attack: attackers impersonating a real development-shop owner posed as an EdTech client and shared a Dropbox folder containing a git repository with a legitimate-looking project spec, but with a real post-checkout hook planted in .git/hooks alongside the usual .example samples. Cloning the repo triggered the hook, which called a Vercel app acting as command-and-control to download an OS-specific binary, make it executable, run it, and self-delete — apparently aiming at the author's GitHub access and client credentials; he reported the accounts to Dropbox and Vercel. The surrounding snippets show adjacent developer-targeting campaigns (typosquatted npm packages, a Microsoft-reported malicious Next.js repo campaign that also abuses Vercel for staging, and TrapDoor's use of git hooks for persistence), but none confirms additional victims of this specific campaign or any platform-level response to checkout-time hook execution.

Why it matters to Scott

Scott's own canon already carries the governing position — ip:concept.sandboxed-execution and dev:technology.bubblewrap structurally sever exactly this payload path (C2 fetch, binary execution, credential reach) for his repo-cloning agents, so the attack confirms rather than challenges or extends him. What it adds is a dated first-party receipt of checkout-hook code execution in the wild — the same primitive radar's GitSpawn case only claimed against coding agents — citable ammunition for the SiloOS / Breach-Doesn't-Compose arguments, and a concrete nudge to neuter or strip hooks on any untrusted clone his harnesses perform.
ip:concept.sandboxed-executiondev:technology.bubblewrapdev:concept.padded-cell-agent-architectureip:framework.siloosradar:gitspawn-repository-agent-hijackradar:concept.software-supply-chainradar:concept.supply-chain-securityradar:concept.agent-sandboxingradar:concept.git-workflows
queries asked of Scott's wikis
  • coding agent cloning untrusted repository sandboxing
  • git hooks automatic execution security risk
  • agent harness credential and secret exposure
  • developer supply-chain attack notes
  • untrusted code execution policy for agents

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 242h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

10-01 14:00⭐ origin echo-reconstructedFirst-person account of a fake EdTech project inquiry whose Dropbox folder contained a .git directory with a single real post-checkout hook:
Frank Wiles on blog (echo) · attributed from hn.story.49952097
—
10-04 09:22first on hacker news · published · +67.4hI got targeted: Trying to get your credentials via a Git post-checkout hook
birdculture
—
10-04 09:22amplified on hacker news 👑hn.story.49952097
birdculture
peak 1 · 0 comments · 106% of case engagement
10-04 11:22our radar first saw it · +69.4hdiscovery anchor: hn.story.49952097—
pace: p8 vs 1188 stories at the 168h mark (now 242h old) — behind addom-local-coding-harness (0.5x)

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnI got targeted: Trying to get your credentials via a Git post-checkout hook
Retrieved article excerpt

Open article · Retrieved 2026-10-04T11:27:01.880865+00:00

# I got targeted

> TL;DR Someone targeted me in an attempt to run arbitrary code on my laptop.
> I suspect in an attempt to gain access to my Github account and/or other
> [REVSYS client](https://www.revsys.com/clients/) related access since I have a
> metric fuck ton of it.

Be careful out there folks. They’re coming and they’re fucking sneaky!

I received a pretty normal project inquiry looking to see if we might be
interested and available to work on a web app project in the Ed Tech space.
We do a fair bit of that work and while we’re pretty booked up, I usually follow
up on these sorts of projects in case the client is able to delay the project
start until we have availablity.

I offered to setup a call with them and gave them a Calendly link. They asked that
I read over the project overview and details prior to the meeting and sign an NDA.

Pretty normal stuff so far.

They then shared a Dropbox folder that had several folders of Markdown files. The
project spec was pretty handwavey and light on details, but fleshed out enough for
the MVP they supposedly wanted.

I initially missed the `.git` folder in that Dropbox link.

When I couldn’t find a NDA or NDA template in the folders I asked for them to email it to me.

They told me:

> We keep it in the NDA branch and just to switch to it, fill it out and return it to them before our meeting

Red flag on a pole under a blue sky

Photo by [أخٌ‌في‌الله](https://unsplash.com/@mhrezaa?utm_source=unsplash&utm_medium=referral&utm_content=creditCopyText) on [Unsplash](https://unsplash.com/photos/red-flag-on-pole-under-blue-sky-during-daytime-GRYHwCxL9wQ?utm_source=unsplash&utm_medium=referral&utm_content=creditCopyText)

This is where I realized what was going on and that this wasn’t a real project. I cruised on over to the `.git/hooks` folder
and sure enough they had all of the `*.example` hooks in there and a single real `post-checkout` hook.

## post-checkout hook, seriously?!?!?!

No one really uses those in practice so I carefully opened it up to see what it was doing.

It was using a Vercel app for [command and control](https://en.wikipedia.org/wiki/Botnet#Command_and_control) where it would
download an OS specific binary, make it executuable, run it, and then delete itself.

I immediately alerted Dropbox and Vercel’s security teams so they can hopefully take these accounts down before they snag
someone. Sadly, they also were impersonating an unspecting development shop owner as part of the ruse.

These assholes didn’t get me today, but I can easily see someone falling for this. Git is such a common workflow for us.

Be extra vigilant and watch your credentials like a hawk. They’re coming for you on some level.

Posted 02 October 2026

[Headshot of Frank Wiles](https://frankwiles.com/ "Frank Wiles Homepage")

[### Frank Wiles](https://frankwiles.com/ "Frank Wiles Homepage")

Founder of [REVSYS](https://www.revsys.com), Django Steering Council, PSF Fellow, and former President of the [Django Software Foundation](https://www.djangoproject.com/foundation/).

Expert in building, scaling and maintaining complex web applications. Want to reach out? [Contact me here](https://frankwiles.com/contact/) or use the social links below.

[Mastodon](https://frankwiles.social/@frank)[GitHub](https://github.com/frankwiles/)[Bluesky](https://bsky.app/profile/fwiles.bsky.social)[X](https://twitter.com/fwiles)

[RSS FeedAll Content](https://frankwiles.com/rss/all.xml "Subscribe to All Content RSS Feed")|[RSS FeedAll Posts](https://frankwiles.com/rss/posts.xml "Subscribe to All Posts RSS Feed")

Infrequent Insights

### Join my newsletter!

Get the occasional email from me when I write something new.

Ask Frank Anything

Struggling with architecture decisions or team dynamics? Ask me any tech, business process, or entrepreneurial question, and I'll do my best to help!

[Submit a Question](https://forms.frankwiles.com/ask-frank)
birdculture10
🟧 echo.blog ⭐First-person account of a fake EdTech project inquiry whose Dropbox folder contained a .git directory with a single real post-checkout hook:Frank Wiles——

Interpretation history

Decision trace