I got targeted
Summary
An author recounts a targeted phishing attempt that used a malicious git post-checkout hook to install a remote binary via a Vercel app, masquerading as a client NDA process. The attacker aimed to gain access to GitHub and RevSys-related access; the piece highlights the importance of scrutinizing project requests and repository hooks. The author reports contacting Dropbox and Vercel security, and warns developers to be vigilant about credential protection.