Attackers Planted Millions of Imageless Repositories on Docker Hub
ID: 8b06af2b-889c-5139-82c8-2601afe702ae
STIX ID: report--8b06af2b-889c-5139-82c8-2601afe702ae
Feed Name: Dark Reading
JFrog researchers found millions of imageless repositories on Docker Hub (nearly 3 million malicious repositories among 4.6 million imageless repos over five years) that contained HTML description pages linking to spam, phishing, and malware sites. The uploads occurred in large campaigns in 2021 and 2023—targeting pirated content, video game cheats, and free e-book phishing—and involved about 208,739 fake accounts and a third actor uploading ~1,000 repositories daily for three years; Docker has since blocked embedding external links in imageless repository descriptions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
