Black Hat 2017 Security experts develop GitPwnd, a tool that could be used by attackers to communicate with compromised devices via Git repositories. The experts highlighted that the problem is very serious in software development environments that adopt the Agile methodology. The attackers can abuse Git hooks that scripts that run automatically when a developer runs Git commands in a repository, malicious changes to hooks are difficult to discover because their codes are not under version control. The hackers can then run arbitrary Python commands to exfiltrate data or to perform other malicious activities.”]
Source: http://securityaffairs.co/wordpress/61684/hacking/gitpwnd-hacking-tool-github.html