{"id":14087,"date":"2026-05-12T14:08:05","date_gmt":"2026-05-12T14:08:05","guid":{"rendered":"https:\/\/www.europesays.com\/korea\/14087\/"},"modified":"2026-05-12T14:08:05","modified_gmt":"2026-05-12T14:08:05","slug":"north-korea-hackers-abuse-git-hooks-to-deploy-cross-platform-malware","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/korea\/14087\/","title":{"rendered":"North Korea Hackers Abuse Git Hooks to Deploy Cross-Platform Malware"},"content":{"rendered":"<p>North Korean threat actors have introduced a stealthy new delivery mechanism in their ongoing \u201cContagious Interview\u201d campaign, shifting tactics to abuse Git hooks for malware execution. <\/p>\n<p>The attack begins with a <a href=\"https:\/\/gbhackers.com\/tsundere-bot-malware\/\" type=\"post\" id=\"176429\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">familiar social engineering lure<\/a>. Victims, often developers targeted through fake job interviews, are asked to clone a GitHub repository containing a \u201ccoding assessment.\u201d Hidden within the repository is a malicious\u00a0.git hooks\/pre-commit\u00a0script. <\/p>\n<p>Unlike bulky payloads used in earlier campaigns, this script is intentionally minimal. It fingerprints the victim\u2019s operating system using the\u00a0uname -s\u00a0command. <\/p>\n<p>Instead, they are embedding a lightweight loader inside Git pre-commit hooks, allowing malware to execute before a developer even finalizes a commit.<\/p>\n<p>It retrieves a platform-specific payload from a remote server hosted at\u00a0precommit[.]vercel.app. Depending on the OS, the script uses tools like\u00a0curl\u00a0or\u00a0wget\u00a0to fetch and execute the next-stage malware directly in the shell or Windows command environment.<\/p>\n<p>Security researchers from the OpenSourceMalware <a href=\"https:\/\/opensourcemalware.com\/blog\/dprk-git-hooks-malware\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">team report that attackers are no longer relying on VS Code task files<\/a>, npm postinstall scripts, or disguised font files. <\/p>\n<p>This design allows attackers to deliver tailored payloads: Bash scripts for macOS and Linux systems, and batch-compatible commands for Windows environments running Git Bash, MSYS, or Cygwin. <\/p>\n<p>The inclusion of a\u00a0flag=5\u00a0parameter in the URL likely helps operators track campaign variants or infection sources, a tactic observed in earlier DPRK-linked operations.<\/p>\n<p>A key feature of the malicious hook is its stealth. All output is redirected to\u00a0\/dev\/null, ensuring no visible signs of execution. <\/p>\n<p>Additionally, the script always returns a successful exit code, allowing the Git commit process to proceed normally. This minimizes suspicion, as developers see no errors or interruptions.<\/p>\n<p>The use of\u00a0precommit[.]vercel.app\u00a0adds another layer of deception. The domain appears legitimate at first glance, mimicking the widely used \u201cpre-commit\u201d framework. <\/p>\n<p>However, it is actually a disposable Vercel deployment controlled by attackers, enabling them to host and rotate payloads with minimal infrastructure dynamically.<\/p>\n<p>Git Hooks Abused<\/p>\n<p>Git hooks provide an ideal execution point for attackers. They are deeply integrated into developer workflows and commonly used in modern projects through tools like Husky and lint-staged. As a result, the presence of a\u00a0.githooks\u00a0directory rarely raises suspicion.<\/p>\n<p>More importantly, hooks execute automatically during routine actions like committing code precisely the behavior expected in a coding assignment. <\/p>\n<p>Many developers configure hooks using\u00a0git config core.hooksPath .githooks\u00a0without inspecting their contents, creating an easy path for exploitation.<\/p>\n<p>This shift also helps attackers bypass recent security improvements in development tools. As <a href=\"https:\/\/gbhackers.com\/visual-studio-code-2\/\" type=\"post\" id=\"175552\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">platforms like Visual Studio Code<\/a> tighten controls around auto-executing tasks, threat actors are pivoting to less scrutinized features within the software development lifecycle.<\/p>\n<p>These repositories follow a consistent pattern: minimal commit history, realistic project structures, and tasks requiring local code execution.<\/p>\n<p>In some cases, attackers also deploy\u00a0post-checkout\u00a0hooks, which trigger whenever a user switches branches making them even more dangerous due to their frequent execution.<\/p>\n<p>Researchers <a href=\"https:\/\/gbhackers.com\/lnk-phishing-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified multiple GitHub<\/a> containing identical malicious pre-commit hooks, all linked to newly created accounts and themed around cryptocurrency or DeFi projects. <\/p>\n<p>This campaign highlights the growing risk of supply chain-style attacks targeting individual developers. Security experts strongly advise treating any interview-related repository as potentially malicious, especially in high-risk sectors like crypto and Web3.<\/p>\n<p>Before running or committing code, developers should inspect directories such as\u00a0.githooks,\u00a0.husky, and\u00a0.vscode, along with any installation scripts. <\/p>\n<p>Executing unknown projects inside isolated virtual machines without access to sensitive credentials, SSH keys, or crypto wallets can significantly reduce risk.<\/p>\n<p>The evolution of the Contagious Interview campaign underscores how threat actors continue to exploit trust in everyday development tools turning routine workflows into powerful infection vectors.<\/p>\n<p>IOCs<\/p>\n<p>TypeIndicator \/ ValueC2 URLhxxps:\/\/precommit[.]vercel.app\/settings\/mac?flag=5C2 URLhxxps:\/\/precommit[.]vercel.app\/settings\/linux?flag=5C2 URLhxxps:\/\/precommit[.]vercel.app\/settings\/windows?flag=5C2 Domainprecommit[.]vercel.appFile path.githooks\/pre-commitFile hash (SHA-256)3ebd9bb57d155cc7c3353660f54c153a094cdfbd<\/p>\n<p>Note:\u00a0IP addresses and domains are intentionally defanged (e.g.,\u00a0[.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\">Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEV2RpYUdGamEyVnljeTVqYjIwb0FBUAE?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cyber-threat-intel\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and\u00a0<a href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get Instant Updates and Set GBH as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=https:\/\/gbhackers.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"North Korean threat actors have introduced a stealthy new delivery mechanism in their ongoing \u201cContagious Interview\u201d campaign, shifting&hellip;\n","protected":false},"author":2,"featured_media":14088,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[5033,10454,31,3110,34],"class_list":["post-14087","post","type-post","status-publish","format-standard","has-post-thumbnail","category-north-korea","tag-cyber-security","tag-cyber-security-news","tag-korea","tag-malware","tag-north-korea"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/posts\/14087","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/comments?post=14087"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/posts\/14087\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/media\/14088"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/media?parent=14087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/categories?post=14087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/tags?post=14087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}