Lazarus uses Git Hooks to hide malicious software attacks on developers
According to research by OpenSourceMalware, the North Korean hacker group Lazarus concealed the second stage loader in pre commit scripts of Git Hooks during activities such as "Infectious Interview" and "TaskJacker". Infectious Interview "induces developers to clone malicious code repositories to steal encrypted assets and credentials by forging the recruitment process of cryptocurrency/DeFi. Researchers suggest that developers run such repositories in isolated environments to avoid exposing browser configurations, SSH keys, and encrypted wallets.