# The Requirements File Was Clean. The Git Hook Was the Trap.

**Summary:** A fake take-home interview hid its downloader in Git metadata, which is why I now treat unfamiliar project archives as untrusted before the first editor or Git action.

- Canonical: https://markhuang.ai/news/clean-requirements-git-hook-trap
- Language: en
- Author: [Mark Huang](https://markhuang.ai/about)
- Published: 2026-07-24
- Section: News
- Tags: Cybersecurity, Developer Tools, Git, Job Scams, Malware
- Source: [Appaji C.](https://citizendot.github.io/articles/fake-job-interview-git-hook-malware/)
- License: https://creativecommons.org/licenses/by-nc/4.0/

---

The hidden Git hook inside a fake take-home interview project

## The offer looked plausible

![Six panels follow a reported recruitment lure from an unsolicited Python role and unusually high monthly pay through a credible company name, a polished assignment, an ordinary-looking backend, and Mark's decision to stop before trusting the archive.](https://cdn.markhuang.ai/news/clean-requirements-git-hook-trap/comic-page-01.webp)

**Mode:** Reported facts

Appaji C. reports that an unsolicited recruiter offered a remote Python role paying $10,000 to $15,000 per month. The claimed employer was a Y Combinator startup, and the take-home arrived as a polished PDF plus a project archive on Google Drive. The speed bothers me: borrowed credibility can make an unfamiliar archive feel safer than it is.

### Panels

1. Mark studies blank message cards on a laptop, representing the unsolicited LinkedIn recruiter pitch described by the source. (caption: The report begins with an unsolicited LinkedIn pitch for Python work.)
2. A laptop, contract folder, and tall stacks of coins represent the remote role's unusually large monthly pay range. (caption: The offer promised $10,000 to $15,000 per month for remote work.)
3. Mark considers a polished startup office and an empty badge shape, visualizing the credibility borrowed from the claimed company. (caption: The claimed company was a Y Combinator startup, adding credibility.)
4. A resume moves through a rapid approval checkpoint toward a cloud folder and zipped archive. (caption: A polished PDF and project archive followed through Google Drive.)
5. An ordinary folder sits beside a tidy backend architecture model made from neutral connected blocks. (caption: The visible backend and dependency list looked ordinary at first.)
6. Mark raises a hand before touching a project block sitting inside an open mechanical trap. (thought: I treat that polish as packaging, not permission.)

### Sources

- [Appaji C.: fake interview Git hook investigation](https://citizendot.github.io/articles/fake-job-interview-git-hook-malware/)

---

## The trap lived below the code

![Six panels move from a clean dependency check into hidden repository metadata, a malicious pre-commit hook, operating-system-specific downloads, a remote payload, and the Git tasks that the source author concluded were intended to trigger the hook.](https://cdn.markhuang.ai/news/clean-requirements-git-hook-trap/comic-page-02.webp)

**Mode:** Technical mechanism

The archive's visible FastAPI project and requirements file looked ordinary. A hidden-file listing revealed a bundled .git directory with many hooks, including a pre-commit script that chose a download command by operating system and fetched remote code. Git documents pre-commit as a hook invoked by git commit, which explains why an assignment containing Git tasks could provide the trigger.

### Panels

1. Mark compares a checklist of ordinary package blocks with the visible project structure. (caption: The requirements file showed no obvious malicious packages.)
2. Mark opens a concealed drawer beneath a physical file tree and finds a hidden repository folder. (caption: Listing hidden files exposed a bundled repository directory.)
3. Mark points toward one active lever among many hook mechanisms inside a dark cabinet. (caption: Its pre-commit hook downloaded code from a raw IP address.)
4. One trigger branches toward three kinds of computer and then connects to a distant red endpoint. (caption: The hook selected a payload for each host operating system.)
5. Mark keeps his hands away as a red parcel travels down a cable into hidden gears on a computer. (caption: A commit could start the download before application code ran.)
6. A blank assignment diagram routes several Git-like operations toward a trigger lever while Mark recognizes the connection. (caption: The author concluded the Git tasks were meant to trigger hooks.)

### Sources

- [Appaji C.: hook and payload analysis](https://citizendot.github.io/articles/fake-job-interview-git-hook-malware/)
- [Git documentation: hooks](https://git-scm.com/docs/githooks)

---

## The downloader was clearer than the motive

![Six panels trace the reported Linux downloader into a second-stage script, show different responses tied to request identifiers, examine suspicious dependencies, separate observed behavior from speculation, and end at a server whose three open ports did not establish attribution.](https://cdn.markhuang.ai/news/clean-requirements-git-hook-trap/comic-page-03.webp)

**Mode:** Evidence and limits

The source directly observed a Linux script saving and launching a second payload, which then installed tooling and ran an obfuscated parser. Changing the request identifier produced a different script, suggesting per-target variation. The dependencies raised reasonable concern about credential or crypto theft, but the article did not prove the final objective or identify the operator. That is where I stop the claim.

### Panels

1. Mark places a sealed red payload inside a documents drawer beside a hidden background gear. (caption: The first script saved and launched a second Linux payload.)
2. Mark assembles a runtime block and package box beside tangled ribbons that represent an obfuscated parser. (caption: That stage installed tooling and started an obfuscated parser.)
3. Four distinct identity tokens reach one server and receive four differently colored sealed parcels. (caption: Changing the request identifier returned a different script.)
4. Mark compares a blank dependency graph with clipboard and crypto-development symbols, without assigning a final purpose. (caption: Suspicious dependencies hinted at theft, but did not prove it.)
5. Mark stops at a bright evidence boundary between observed downloader stages and a dark unknown objective. (thought: I can trace the downloads, but not the final objective.)
6. A locked server cabinet with three lit connection ports stands at the end of a cold trail. (caption: Three open ports did not reveal who ran the server.)

### Sources

- [Appaji C.: staged payload evidence](https://citizendot.github.io/articles/fake-job-interview-git-hook-malware/)
- [Paradane: separate fake interview campaign analysis](https://paradane.com/blog/ming-or-job-scam-malware-campaign)

---

## A known pattern, not a proven operator

![Six panels place the reported sample inside a recruitment-malware pattern documented since December 2022, compare several execution routes, preserve the limit on actor attribution, show a restricted editor, and move the trust decision ahead of every developer tool.](https://cdn.markhuang.ai/news/clean-requirements-git-hook-trap/comic-page-04.webp)

**Mode:** Public context

Microsoft says the Contagious Interview campaign has operated since at least December 2022 and uses staged recruiting to persuade developers to run malicious packages or commands. That context makes this report plausible, but it does not prove who operated this particular server. VS Code's Restricted Mode matters because it limits tasks, terminals, debugging, workspace settings, extensions, and agents while an unfamiliar folder is reviewed.

### Panels

1. A long path carries several staged recruiter encounters toward sealed coding exercise boxes in the distance. (caption: Microsoft traces this campaign pattern to December 2022.)
2. Four recruitment stages unfold across a theater while a concealed mechanical trap waits beneath the final step. (caption: The lure works by copying a normal recruiting sequence.)
3. Three sealed assignment boxes connect separately to a package gear, a Git-hook lever, and an editor-task gear. (caption: Packages, Git hooks, and editor tasks can all become triggers.)
4. Mark draws a bright evidence boundary around the reported archive while an unidentified shadow remains outside it. (caption: This sample fits the pattern; its operator remains unproven.)
5. Mark reviews an unfamiliar sealed folder beside unplugged tools and a blank dark monitor in a restricted workspace. (caption: Restricted Mode limits tasks, terminals, debugging, and agents.)
6. Mark stops at a gate between an unopened assignment folder and inactive developer computers. (thought: I want the trust decision before any developer tool runs.)

### Sources

- [Microsoft Security: Contagious Interview](https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/)
- [Visual Studio Code: Workspace Trust](https://code.visualstudio.com/docs/editing/workspaces/workspace-trust)
- [Appaji C.: reported sample](https://citizendot.github.io/articles/fake-job-interview-git-hook-malware/)

---

## Move inspection ahead of trust

![Six panels turn the investigation into a safer take-home workflow: isolate the archive, inspect hidden files before opening an editor, check likely execution surfaces, keep credentials away, monitor the isolated run, and protect the main workstation.](https://cdn.markhuang.ai/news/clean-requirements-git-hook-trap/comic-page-05.webp)

**Mode:** Practical recommendation

I now open recruiter-provided code only inside a disposable, isolated environment, then inspect hidden directories and likely execution surfaces before using an editor or running Git. Microsoft recommends non-persistent virtual machines for coding tests, keeping them away from production credentials, and monitoring suspicious command or network activity. A clean dependency file is only one check.

### Panels

1. Mark places a sealed assignment archive inside a transparent sandbox that is disconnected from his main computer. (caption: Open take-home projects in a disposable, isolated environment.)
2. Mark uses a magnifying glass to inspect every layer of a transparent file tree before opening an editor. (caption: Inspect hidden directories before opening the project in an editor.)
3. Mark checks three abstract execution surfaces represented by a hook, a cluster of task gears, and a package lifecycle. (caption: Review hooks, editor tasks, and package lifecycle scripts first.)
4. A stone wall separates Mark and several credential-shaped keys from the isolated test environment. (caption: Keep production credentials and long-lived tokens off that machine.)
5. Mark watches a sealed assignment run inside a transparent sandbox while abstract network pulses remain visible. (caption: Run only after inspection, with network activity still monitored.)
6. Mark calmly reviews a guarded path from sealed archive to inspection gate to isolated execution, away from his main computer. (thought: The assignment can wait; my workstation should not take the risk.)

### Sources

- [Microsoft Security: defensive recommendations](https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/)
- [Visual Studio Code: Restricted Mode](https://code.visualstudio.com/docs/editing/workspaces/workspace-trust)
- [Git documentation: pre-commit hook](https://git-scm.com/docs/githooks)
