“Repo Squatting”: How Hackers Are Using GitHub’s Own Features to Hijack Official Repos
ID: 820fc7bc-cdd4-5ccb-aa10-2cdf808867d7
STIX ID: report--820fc7bc-cdd4-5ccb-aa10-2cdf808867d7
Feed Name: securityonline.info
Threat Score
A GMO Cybersecurity report documents a “repo squatting” supply-chain style campaign where attackers exploited GitHub’s fork/commit URL behavior to host a malicious GitHub Desktop installer containing the HijackLoader multi-stage loader; the technique made malicious downloads appear to originate from the official repository, was active in Sep–Oct 2025, and remained reproducible as of Dec 29, 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
