A Fake NDA 'Branch' Carried a Git post-checkout Hook That Fetched a Binary From Vercel
Security / news
A Fake NDA 'Branch' Carried a Git post-checkout Hook That Fetched a Binary From Vercel
Frank Wiles of REVSYS found the hook before checking out the branch. It only works if the victim receives the .git folder itself.
A shared folder that contains a .git directory can run an attacker's binary on your machine the moment you switch branches, provided you copy the folder as it is and do not clone it from a remote. Django Steering Council member Frank Wiles hit exactly that on Oct. 2, and stopped before it ran.
Wiles, founder of REVSYS and a former Django Software Foundation president, wrote that a prospective Ed Tech client asked him to review an NDA before booking a call on Calendly. The client shared a Dropbox folder of Markdown project specifications and said the NDA lived on an "NDA branch" of the repository inside it.
What the hook did
Wiles looked in .git/hooks before checking out the branch and found a post-checkout file next to the usual .sample templates. By his description it downloaded an operating-system-specific binary from an application hosted on Vercel, marked it executable, ran it, and deleted itself.
He said the project specification was suspiciously vague and that the sender appeared to be impersonating the owner of a real development shop. He did not run the binary. His post says the likely targets were his GitHub access and REVSYS client accounts.
The branch request is the trigger. Git's documentation says post-checkout is invoked when git checkout or git switch runs after updating the worktree. It also runs after git clone, unless --no-checkout is used.
Why this is not a git flaw
Hooks are local configuration. The githooks manual says git init may copy hooks into a new repository depending on its template directory, and otherwise a hook is not part of what a remote delivers. A repository you clone from GitHub does not bring its author's hooks with you.
That is why the Dropbox folder matters. A hook in .git/hooks only reaches you if someone hands you the .git directory itself, which is what a synced folder does. This is an inference from the two documents, not something Wiles tested.
The same manual says the hooks directory can be moved with the core.hooksPath setting, which also means a hook can live somewhere a casual look at .git/hooks will miss.
How it compares with known developer lures
Microsoft's March 11, 2026 write-up of the Contagious Interview campaign, which it attributes with high confidence to North Korean actors, describes fake recruiters pushing developers toward repositories on GitHub, GitLab and Bitbucket. Microsoft's post names npm installs and VS Code task files as the triggers. It does not mention git hooks.
Wiles did not attribute his attack to anyone, and nothing in his post ties it to that campaign. The shape is similar: a plausible business pretext, a request that makes you run something, and credentials as the prize.
| Trigger | Source | What the victim does |
|---|---|---|
post-checkout hook in a copied .git | Wiles, Oct. 2 | Switches to the "NDA branch" |
| VS Code task file | Microsoft, March 11 | Trusts the repository's author when prompted |
| Malicious npm package | Microsoft, March 11 | Installs or runs the project |
Microsoft's credential list for its campaign covers API tokens, cloud credentials, signing keys, wallets and password manager artifacts. It advises running recruiter-supplied code in isolated environments and reviewing repositories before running anything.
What to check before you switch branches
Obtain repositories with git clone from a remote, not as a zipped or synced folder. If you are handed a folder anyway, list .git/hooks and treat any file without a .sample suffix as code to read first. Check git config core.hooksPath as well.
Wiles's closing advice to other developers was to watch credentials "like a hawk". Sandboxing is the structural version of that advice, as in NVIDIA's OpenShell, and Apple now says Full Disk Access will need explicit user action.
Sources
More in Security
- 01NetScaler CVE-2026-88779 Is Rated Denial of Service, but a Researcher Reports a Payload DownloadCitrix patched a SAML memory overflow on October 3 and 4 after attacks began. CISA gave agencies until October 7, and the appliances patched last week for CVE-2026-88771 through CVE-2026-88778 need updating again.
- 02Cisco SD-WAN Manager Flaw CVE-2026-76504 Needs One Encoded Character for Admin API Access, With No WorkaroundCisco's PSIRT found exploitation during a support case in September. Six release trains have fixes, and the vendor and two security firms count Cisco's earlier SD-WAN flaws differently.
- 03Two Zammad Zero-Days Took an Attacker From Session Hijack to Root at the Dutch Institute for Vulnerability DisclosureCISA put CVE-2026-102489 and CVE-2026-102490 in its exploited catalog on October 2. DIVD says an AI agent, not a person, ran the intrusion it found on its own ticketing system.
- 04Citrix NetScaler Zero-Days Are Exploited Without Credentials, and Web Shells Survive the PatchCVE-2026-88771 and CVE-2026-88772 both score 9.5. Citrix shipped fixed builds on September 27, but researchers say implants planted earlier persist through the update.