You switched to the branch the "client" asked you to open. Or you ran npm install on their demo, or clicked "trust" when your editor asked. Now something looks wrong. This is the first hour, in order, written from what we prepared when a fake client targeted our agency on September 29, 2026 (the story is here). We were lucky and never needed it. If you're reading this with a knot in your stomach, start at the top and don't skip ahead.
One rule runs through all of it: the machine you think is compromised is not the machine you fix things from. Anything you type on it, including new passwords, may be read.
Minutes 0 to 5: confirm it, then cut it off
First, a quick look for the tell-tale files. For the lure we analysed, these appear in your temp folder (echo $TMPDIR on a Mac, /tmp on Linux, %TEMP% on Windows):
run-command.shorrun-command.cmd.git-checker
Other campaigns drop other names, so also look for anything created in the last hour in your temp folder and in ~/Library/LaunchAgents on a Mac, which is where persistence often lands.
Then disconnect the machine from the network: Wi-Fi off, cable out. Don't shut it down and don't wipe it yet. A powered-on, offline machine keeps evidence you may want later, and it can no longer send anything out.
Take photos of anything on screen and note the time you ran the command. You'll want both when you report it.
Minutes 5 to 20: rotate credentials from a different device
Assume anything the compromised machine could read has been copied. The FBI's advisory on this campaign says the same: if infected, assume exfiltration. Work from a phone or a different computer, in this order:
| Order | What | Why this early |
|---|---|---|
| 1 | Email account and password manager | They reset everything else |
| 2 | GitHub, GitLab or Bitbucket: tokens, SSH keys, active sessions | Source access for every client |
| 3 | Cloud consoles and CLI keys (AWS, GCP, Azure, Vercel and similar) | Often stored in plain files like ~/.aws/credentials |
| 4 | Package registry tokens (npm, PyPI) | A stolen publish token can spread malware to others |
| 5 | Client VPNs, admin panels, shared vaults | The part that makes this an agency problem |
| 6 | "Sign out of all sessions" on Google, Microsoft, Slack | Stolen browser cookies can bypass passwords |
| 7 | Crypto wallets | Move funds to a new wallet created on a clean device |
Revoke first, then reissue. A new key is only useful once the old one no longer works.
Minutes 20 to 40: work out what the machine could reach
Now write down, honestly, what was on that laptop. For an agency this list is usually longer than you expect:
- Every client repository cloned on it, and any
.envfiles inside them ~/.ssh,~/.aws,~/.kube,~/.configand any CLI that stays logged in- Browsers logged into client dashboards, hosting panels or email
- Shared drives synced to the machine
Then check the logs that will tell you whether anything was used: the security log on your GitHub account, your cloud provider's audit trail (CloudTrail on AWS, for example), and recent sign-in activity on email. You're looking for access from places and times that aren't you.
Minutes 40 to 60: tell the people who need to know
This is the step people put off, and it matters most for a business that holds other people's keys.
- Clients whose credentials were on the machine. A short, factual note is enough: what happened, when, what you've rotated, and what they should rotate on their side. Telling them early is the difference between an incident and a breach of trust.
- Your cyber insurer, if you have a policy. Many require prompt notice.
- The FBI's IC3 (ic3.gov), and your local police if money was lost. The advisory asks victims to report.
- The platforms involved: the host of the file, the registrar of the sender's domain, and the lead source, so they can stop the next one.
Keep the original email and the file (don't delete them, and don't open them again). Investigators may ask.
After the first hour: rebuild, don't clean
It's tempting to delete the suspicious files and carry on. Don't. Once unknown code has run with your permissions, you can't be sure what else it left behind, and the advisory recommends a full operating-system reset. Back up your documents (not applications, not dotfiles you haven't read), reinstall the OS, and restore data onto a clean system with the new credentials.
It's a painful day. It's a much less painful day than the one where a client finds out from someone else.
If this has happened to your team and you'd like help with the clean-up or with the client conversations that follow, our cybersecurity team can help, and you can reach us directly through the contact page. To stop the next one before it runs, start with the ten-minute repo triage and nine checks for fake client inquiries.