GitHub Research Reveals Millions Vulnerable to RepoJacking
ID: e38f3b37-1454-5d85-a5d0-4bc567c7dd91
STIX ID: report--e38f3b37-1454-5d85-a5d0-4bc567c7dd91
Feed Name: Aqua Security Blog
### Executive summary This research describes 'RepoJacking', a widespread GitHub dependency-repository hijacking technique where attackers claim previously used organization names and repositories (breaking redirects) to serve malicious code; the authors sampled GHTorrent data, found 36,983 vulnerable repositories in a 1% sample (≈2.95%), ran PoCs that resulted in code execution in some environments, presented real-world examples (Lyft, Google, VSCode extension), described bypasses to GitHub protections, and recommended mitigations such as retaining previous organization names and auditing links to external GitHub resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
