Skip to content
New Git Exploitation Tools Released: GitHacker and Pwdlyser

New Git Exploitation Tools Released: GitHacker and Pwdlyser

First seen 25 Sep 2026, 10:24 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 25, 2026 at 10:54 UTC
  • •GitHacker can recover complete Git repositories from `.git` directories.
  • •Pwdlyser analyzes passwords from Active Directory and databases for security assessments.
  • •Both tools are publicly available, increasing the risk of misuse by malicious actors.

Two new cybersecurity tools, GitHacker and Pwdlyser, have been released, targeting vulnerabilities in Git repositories and password analysis respectively. GitHacker allows users to exploit `.git` directories to recover entire repositories, including source code and commit history, even when directory listings are disabled. It has been benchmarked against other tools and reportedly recovers 100% of artifacts in various scenarios. Pwdlyser is designed for security professionals to analyze passwords from Active Directory accounts and databases, providing detailed reports and metrics on password strength. Both tools are aimed at improving security assessments and can potentially be misused for malicious purposes. Security teams are advised to be aware of these tools and their capabilities. The tools are available for public use, raising concerns about their potential for abuse in cyberattacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-24
GitHacker released
GitHacker tool launched, capable of exploiting `.git` directories to recover full repositories.
Sploitus
2026-09-25
Pwdlyser released
Pwdlyser tool launched for analyzing passwords from Active Directory and databases.
Sploitus

More articles in this cluster (2)

Following this threat?

Track GitHacker in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed