Skip to content
← Back to blog
Security·September 30, 2026·5 min read

You opened a suspicious repo. Here's the first hour, minute by minute.

Checked out a branch or ran npm install on a stranger's repo and something looks wrong? What to check, what to rotate, in what order, and who to tell.

You switched to the branch the "client" asked you to open. Or you ran npm install on their demo, or clicked "trust" when your editor asked. Now something looks wrong. This is the first hour, in order, written from what we prepared when a fake client targeted our agency on September 29, 2026 (the story is here). We were lucky and never needed it. If you're reading this with a knot in your stomach, start at the top and don't skip ahead.

One rule runs through all of it: the machine you think is compromised is not the machine you fix things from. Anything you type on it, including new passwords, may be read.

Minutes 0 to 5: confirm it, then cut it off

First, a quick look for the tell-tale files. For the lure we analysed, these appear in your temp folder (echo $TMPDIR on a Mac, /tmp on Linux, %TEMP% on Windows):

  • run-command.sh or run-command.cmd
  • .git-checker

Other campaigns drop other names, so also look for anything created in the last hour in your temp folder and in ~/Library/LaunchAgents on a Mac, which is where persistence often lands.

Then disconnect the machine from the network: Wi-Fi off, cable out. Don't shut it down and don't wipe it yet. A powered-on, offline machine keeps evidence you may want later, and it can no longer send anything out.

Take photos of anything on screen and note the time you ran the command. You'll want both when you report it.

Minutes 5 to 20: rotate credentials from a different device

Assume anything the compromised machine could read has been copied. The FBI's advisory on this campaign says the same: if infected, assume exfiltration. Work from a phone or a different computer, in this order:

OrderWhatWhy this early
1Email account and password managerThey reset everything else
2GitHub, GitLab or Bitbucket: tokens, SSH keys, active sessionsSource access for every client
3Cloud consoles and CLI keys (AWS, GCP, Azure, Vercel and similar)Often stored in plain files like ~/.aws/credentials
4Package registry tokens (npm, PyPI)A stolen publish token can spread malware to others
5Client VPNs, admin panels, shared vaultsThe part that makes this an agency problem
6"Sign out of all sessions" on Google, Microsoft, SlackStolen browser cookies can bypass passwords
7Crypto walletsMove funds to a new wallet created on a clean device

Revoke first, then reissue. A new key is only useful once the old one no longer works.

Minutes 20 to 40: work out what the machine could reach

Now write down, honestly, what was on that laptop. For an agency this list is usually longer than you expect:

  • Every client repository cloned on it, and any .env files inside them
  • ~/.ssh, ~/.aws, ~/.kube, ~/.config and any CLI that stays logged in
  • Browsers logged into client dashboards, hosting panels or email
  • Shared drives synced to the machine

Then check the logs that will tell you whether anything was used: the security log on your GitHub account, your cloud provider's audit trail (CloudTrail on AWS, for example), and recent sign-in activity on email. You're looking for access from places and times that aren't you.

Minutes 40 to 60: tell the people who need to know

This is the step people put off, and it matters most for a business that holds other people's keys.

  • Clients whose credentials were on the machine. A short, factual note is enough: what happened, when, what you've rotated, and what they should rotate on their side. Telling them early is the difference between an incident and a breach of trust.
  • Your cyber insurer, if you have a policy. Many require prompt notice.
  • The FBI's IC3 (ic3.gov), and your local police if money was lost. The advisory asks victims to report.
  • The platforms involved: the host of the file, the registrar of the sender's domain, and the lead source, so they can stop the next one.

Keep the original email and the file (don't delete them, and don't open them again). Investigators may ask.

After the first hour: rebuild, don't clean

It's tempting to delete the suspicious files and carry on. Don't. Once unknown code has run with your permissions, you can't be sure what else it left behind, and the advisory recommends a full operating-system reset. Back up your documents (not applications, not dotfiles you haven't read), reinstall the OS, and restore data onto a clean system with the new credentials.

It's a painful day. It's a much less painful day than the one where a client finds out from someone else.

If this has happened to your team and you'd like help with the clean-up or with the client conversations that follow, our cybersecurity team can help, and you can reach us directly through the contact page. To stop the next one before it runs, start with the ten-minute repo triage and nine checks for fake client inquiries.

Sources

Frequently asked questions.

Check your temp folder for unfamiliar files created in the last hour, then disconnect the machine from the network without shutting it down or wiping it. Photograph anything on screen and note the time. Then move to a different device before changing any passwords.

Start with your email account and password manager, because they can reset everything else. Then revoke and reissue source-control tokens and SSH keys, cloud and CLI keys, package registry tokens, client VPN and admin access, and sign out of all browser sessions. Move any crypto to a new wallet created on a clean device.

We would not. Once unknown code has run with your permissions you cannot be sure what else it left behind, and the FBI advisory on this campaign recommends a full operating-system reset. Back up documents, reinstall the operating system, and restore data onto the clean system.

If their credentials, code or data were reachable from that machine, yes, and early. A short factual note covering what happened, what you have rotated and what they should rotate on their side protects the relationship far better than them hearing about it later.