Attackers Can Generate Duplicate Verified GitHub Commits Using Signature Malleability
ID: 1a59015c-34c6-5960-babf-31651c7fc82f
STIX ID: report--1a59015c-34c6-5960-babf-31651c7fc82f
Feed Name: GBHackers
Researchers demonstrate "Git hash chain malleability": by altering signature encodings (ECDSA, RSA, EdDSA, S/MIME) without changing the signed payload, attackers can create new commit hashes that still validate and receive GitHub's "Verified" badge. Because Git includes signatures in the hashed object, malleated commits and their rewritten descendants produce fresh hashes that bypass SHA-based blocking, pinning, and provenance assumptions, exposing dependency and CI/CD supply-chain controls to stealthy substitution attacks. Defenders should canonicalize and verify content before applying hash-based deduplication or blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
