logo

“Repo Squatting”: How Hackers Are Using GitHub’s Own Features to Hijack Official Repos

ID: 820fc7bc-cdd4-5ccb-aa10-2cdf808867d7

STIX ID: report--820fc7bc-cdd4-5ccb-aa10-2cdf808867d7

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-27

Date Updated: 2026-04-23

Author: Ddos

...
...

A GMO Cybersecurity report documents a “repo squatting” supply-chain style campaign where attackers exploited GitHub’s fork/commit URL behavior to host a malicious GitHub Desktop installer containing the HijackLoader multi-stage loader; the technique made malicious downloads appear to originate from the official repository, was active in Sep–Oct 2025, and remained reproducible as of Dec 29, 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.