logo

GitLab affected by GitHub-style CDN flaw allowing malware hosting

ID: a48692c6-436f-5d5e-b7f0-cc7ab08c5c67

STIX ID: report--a48692c6-436f-5d5e-b7f0-cc7ab08c5c67

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-04-22

Date Updated: 2026-04-20

Author: Ax Sharma

...
...

BleepingComputer reports that attackers are abusing GitHub and GitLab comment file-attachment features to upload malicious files to the platforms' CDNs; the auto-generated download links mimic official repository paths and remain live even if comments are not posted or deleted, enabling highly convincing malware lures that could impersonate releases for major projects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.