I was seconds away from loosing everything. Got one of my product's repos infected through someone (possibly hacked?). It was interesting case because the code that was forced pushed had obfuscated js code.
Doing any forensic in my own device would have been recipe for disaster for both me and the product and possibly it's users.
Asked ChatGPT, and Claude about the code, they all panicked and refused the actual logic of the malicious code. Decided to
@use_construct as they provide cloud VM with GLM, was able to decode the code.
It was taking all .envs and browser cookies, wallets etc through node script.