I got targeted: Trying to get your credentials via a git post-checkout hook
I got targeted: Trying to get your credentials via a git post-checkout hook
我被盯上了:有人试图通过 git post-checkout 钩子获取我的凭据
I got targeted TL;DR Someone targeted me in an attempt to run arbitrary code on my laptop. I suspect in an attempt to gain access to my Github account and/or other REVSYS client related access since I have a metric fuck ton of it. Be careful out there folks. They’re coming and they’re fucking sneaky!
简而言之,我被盯上了。有人试图在我的笔记本电脑上运行任意代码。我怀疑他们是想借此访问我的 Github 账号和/或其他 REVSYS 客户的相关权限,因为我手头掌握着海量的此类权限。各位,请务必小心。他们正蠢蠢欲动,而且手段极其狡猾!
I received a pretty normal project inquiry looking to see if we might be interested and available to work on a web app project in the Ed Tech space. We do a fair bit of that work and while we’re pretty booked up, I usually follow up on these sorts of projects in case the client is able to delay the project start until we have availability. I offered to setup a call with them and gave them a Calendly link.
我收到了一份非常正常的项目咨询,对方询问我们是否有兴趣并有档期承接一个教育科技领域的 Web 应用项目。我们经常做这类工作,虽然目前档期很满,但我通常还是会跟进此类项目,以防客户愿意推迟项目启动时间,直到我们有空档为止。我提议与他们通话,并发送了一个 Calendly 链接。
They asked that I read over the project overview and details prior to the meeting and sign an NDA. Pretty normal stuff so far. They then shared a Dropbox folder that had several folders of Markdown files. The project spec was pretty handwavey and light on details, but fleshed out enough for the MVP they supposedly wanted. I initially missed the .git folder in that Dropbox link.
他们要求我在会议前阅读项目概览和详情,并签署一份保密协议(NDA)。到目前为止,一切都很正常。随后,他们分享了一个 Dropbox 文件夹,里面包含几个存放 Markdown 文件的子文件夹。项目规格书写得比较笼统,细节不多,但对于他们声称想要的 MVP(最小可行性产品)来说,内容已经足够充实了。起初,我并没有注意到那个 Dropbox 链接里包含一个 .git 文件夹。
When I couldn’t find a NDA or NDA template in the folders I asked for them to email it to me. They told me: We keep it in the NDA branch and just to switch to it, fill it out and return it to them before our meeting.
当我在文件夹中找不到保密协议或协议模板时,我要求他们通过电子邮件发给我。他们却告诉我:保密协议存放在 NDA 分支里,让我切换到该分支,填好后再在会议前发回给他们。
This is where I realized what was going on and that this wasn’t a real project. I cruised on over to the .git/hooks folder and sure enough they had all of the *.example hooks in there and a single real post-checkout hook. post-checkout hook, seriously?!?!?! No one really uses those in practice so I carefully opened it up to see what it was doing.
就在这时,我意识到发生了什么——这根本不是一个真实的项目。我查看了 .git/hooks 文件夹,果然,里面不仅有所有的 *.example 钩子文件,还有一个真实的 post-checkout 钩子。post-checkout 钩子,认真的吗?!在实际开发中根本没人会用这个,于是我小心翼翼地打开它,看看它到底在搞什么鬼。
It was using a Vercel app for command and control where it would download an OS specific binary, make it executable, run it, and then delete itself. I immediately alerted Dropbox and Vercel’s security teams so they can hopefully take these accounts down before they snag someone. Sadly, they also were impersonating an unsuspecting development shop owner as part of the ruse.
它利用一个 Vercel 应用作为命令与控制中心(C2),下载一个特定于操作系统的二进制文件,将其设为可执行文件,运行它,然后自动删除。我立即向 Dropbox 和 Vercel 的安全团队发出了警报,希望他们能在有人受害之前封禁这些账号。遗憾的是,他们还冒充了一位毫无戒心的开发公司老板来实施骗局。
These assholes didn’t get me today, but I can easily see someone falling for this. Git is such a common workflow for us. Be extra vigilant and watch your credentials like a hawk. They’re coming for you on some level.
这些混蛋今天没能得逞,但我完全能预见到有人会掉进这个陷阱。Git 对我们来说是如此常用的工作流。请务必保持高度警惕,像鹰一样盯紧你的凭据。他们正从某种层面上向你袭来。