I got targeted
TL;DR Someone targeted me in an attempt to run arbitrary code on my laptop. I suspect in an attempt to gain access to my Github account and/or other REVSYS client related access since I have a metric fuck ton of it.
Be careful out there folks. They’re coming and they’re fucking sneaky!
I received a pretty normal project inquiry looking to see if we might be interested and available to work on a web app project in the Ed Tech space. We do a fair bit of that work and while we’re pretty booked up, I usually follow up on these sorts of projects in case the client is able to delay the project start until we have availablity.
I offered to setup a call with them and gave them a Calendly link. They asked that I read over the project overview and details prior to the meeting and sign an NDA.
Pretty normal stuff so far.
They then shared a Dropbox folder that had several folders of Markdown files. The project spec was pretty handwavey and light on details, but fleshed out enough for the MVP they supposedly wanted.
I initially missed the .git folder in that Dropbox link.
When I couldn’t find a NDA or NDA template in the folders I asked for them to email it to me.
They told me:
We keep it in the NDA branch and just to switch to it, fill it out and return it to them before our meeting
Photo by أخٌفيالله on Unsplash
This is where I realized what was going on and that this wasn’t a real project. I cruised on over to the .git/hooks folder
and sure enough they had all of the *.example hooks in there and a single real post-checkout hook.
post-checkout hook, seriously?!?!?!
No one really uses those in practice so I carefully opened it up to see what it was doing.
It was using a Vercel app for command and control where it would download an OS specific binary, make it executuable, run it, and then delete itself.
I immediately alerted Dropbox and Vercel’s security teams so they can hopefully take these accounts down before they snag someone. Sadly, they also were impersonating an unspecting development shop owner as part of the ruse.
These assholes didn’t get me today, but I can easily see someone falling for this. Git is such a common workflow for us.
Be extra vigilant and watch your credentials like a hawk. They’re coming for you on some level.

Frank Wiles
Founder of REVSYS, Django Steering Council, PSF Fellow, and former President of the Django Software Foundation.
Expert in building, scaling and maintaining complex web applications. Want to reach out? Contact me here or use the social links below.
Join my newsletter!
Get the occasional email from me when I write something new.
Struggling with architecture decisions or team dynamics? Ask me any tech, business process, or entrepreneurial question, and I'll do my best to help!