The malware was not in the app. It was in .git/hooks.
This incident reinforced one rule for me: never trust a hiring repo just because the frontend looks polished. Verify the hooks, the config, and the delivery path first.
Jul 1, 20268 min read52

Search for a command to run...
Articles tagged with #social-engineering