Read Before You Run
Fixes in issues, chats, tutorials or AI answers can hide harmful commands. Review the command and its source.
Illustrative scenario
How It Looks in Real Life
A comment on a GitHub issue offers a one-line fix that downloads a script and pipes it straight into a shell. The account was created yesterday.
Understand it
How the Attack Works
Attackers post convincing fixes where developers look for help. A single pasted line can download and execute anything with your permissions. AI assistants can also produce insecure commands by mistake.
Red flags
Warning Signs
- Commands that download and immediately execute remote content.
- Encoded or obfuscated strings you cannot read.
- New or anonymous accounts offering urgent “fixes”.
Safer habits
What to Do Instead
- 1Understand every part of a command before running it.
- 2Prefer official documentation and maintainers’ instructions.
- 3Download scripts to inspect them first, and run unknown code only in isolation.
Response playbook
Already Interacted?
For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.
If you: installed software or ran a command
- 1Disconnect the device from the network (Wi-Fi off or cable out) but leave it powered on.
- 2Report to IT or security and describe exactly what you ran or installed.
- 3Do not delete files, wipe the device or run cleanup tools yourself; evidence helps the investigation.
- 4From a different, trusted device, change passwords for accounts used on the affected machine.
If you: exposed a token, key or secret
- 1Revoke or rotate the exposed secret at the provider first; deleting the commit or message is not enough.
- 2Report it to the security team with where and when it was exposed. Never paste the secret itself into the report.
- 3Review provider logs for use of the key after the exposure time.
Knowledge Check
What Would You Do?
A chatbot suggests a long encoded command to fix your build. What is safest?
Fictional example for learning. Not a test score or certification.
Sources
- Microsoft Security Blog: Think before you ClickFix (Aug 2025)
- GitHub Blog: Social engineering campaign targets technology employees
Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.
Make Safe Habits Part of Your Culture
Plain-language awareness sessions for everyday staff, developers and business teams.