No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Millions of Repos on GitHub Are Potentially Vulnerable to Hijacking

June 23, 2023
in Protection
0
Millions of Repos on GitHub Are Potentially Vulnerable to Hijacking



Millions of enterprise software repositories on GitHub are vulnerable to repojacking, a relatively simple kind of software supply chain attack where a threat actor redirects projects that are dependent on a particular repo to a malicious one instead.

The issue has to do with how GitHub handles dependencies when a GitHub user or organization changes the name of a project or transfers its ownership to another entity, researchers at Aqua Security said in a report this week.

Name-Change Risks

To avoid breaking code dependencies, GitHub creates a link between the original repo name and the new one so all projects that are dependent on the original repo get automatically redirected to the newly renamed one. However, if an organization fails to adequately protect the old username, an attacker could simply reuse it to create a trojanized version of the original repository so that any projects that relied on the repo will once again start downloading dependencies from it.

“When a repository owner changes their username, a link is created between the old name and the new name for anyone who downloads dependencies from the old repository,” Aqua researchers said in a blog this week. “However, it is possible for anyone to create the old username and break this link.”

Researchers at Aqua recently decided to investigate the prevalence of repositories on GitHub that are vulnerable to such repojacking, or dependency repository hijacking, as some security researchers refer to the threat.

Widely Prevalent Issue

What Aqua discovered was twofold: millions of such repositories — including those belonging to companies such as Google and Lyft — are present on GitHub; and tools are easily available to attackers to find these repos and hijack them. One of these tools is GHTorrent, a project that maintains a nearly complete record of all public events, such as commits and pull requests, on GitHub. Attackers can use GHTorrent to harvest the GitHub names of repositories that organization previously used. They can then register the repo under that old username, recreate the repository, and deliver malware to any project that uses it.

Any project that directly references a GitHub repository is vulnerable if the owner of the repository changes or deletes the username for their repository.

“We have presented a significant dataset that attackers can utilize to harvest the names of previous repositories belonging to organizations,” says Yakir Kadkoda, security researcher at Aqua Nautilus.

“Organizations should not assume that their old organization names will remain undisclosed,” warns Kadkoda. “It is crucial for them to claim and keep their old usernames on GitHub and scan GitHub URLs and references in their code to identify any repositories that could potentially be claimed by an attacker.”

Bypassing Protections

Kadkoda says GitHub has attempted to address this issue by preventing the creation of usernames and repositories that were previously owned and now redirect to other projects. GitHub also implemented a mechanism several years ago to retire popular repository namespaces as a means of mitigating this threat. “However, several bypasses have been discovered in the past few years,” he says. During Aqua’s study, its researchers found several examples of repositories where the protection implemented by GitHub did not apply. “Therefore, users cannot fully rely on these defenses at this point,” he says.

Aqua’s blog pointed to a GitHub vulnerability that Checkmarx discovered last year as one example of the ways available to attackers to bypass GitHub’s attempts to protect against repojacking. The flaw involved a mechanism called “popular repository namespace retirement” and affected all renamed usernames on GitHub, including over 10,000 packages on package managers such as Swift, Packagist, and Go. “Repojacking is a technique to hijack renamed repository URLs traffic and routing it to the attacker’s repository by exploiting a logical flaw that breaks the original redirect,” Checkmarx said in a report on the vulnerability. “A GitHub repository is vulnerable to repojacking when its creator decided to rename his username while the old username is available for registration.”

Organizations can mitigate their exposure to the repojacking threat by scanning their code, repositories, and dependencies for GitHub links, Kadkoda says: “They should check if those links directly refer to GitHub projects or if there are redirects pointing to repositories under other usernames or repo names than the original links.” In these instances, organizations should attempt to claim the available username to prevent attackers from doing so. “Additionally, organizations should always maintain their old usernames on GitHub,” he says.

Editorial Team

Editorial Team

Related Posts

These Refurbished AirPods4 (With ANC) Are Just $118 During the Amazon Big Spring Sale
Protection

These Refurbished AirPods4 (With ANC) Are Just $118 During the Amazon Big Spring Sale

March 25, 2026
The Apple Watch Ultra 2 Is Nearly $200 Off for the Amazon Big Spring Sale
Protection

The Apple Watch Ultra 2 Is Nearly $200 Off for the Amazon Big Spring Sale

March 25, 2026
Follow the Best Deals From Amazon's Big Spring Sale in Real Time
Protection

Follow the Best Deals From Amazon’s Big Spring Sale in Real Time

March 25, 2026
This 15-Inch M4 MacBook Air Is $300 Off for the Amazon Big Spring Sale
Protection

This 15-Inch M4 MacBook Air Is $300 Off for the Amazon Big Spring Sale

March 25, 2026
The DJI Osmo 360 Essential Combo Is Over $200 Off for Amazon's Spring Sale
Protection

The DJI Osmo 360 Essential Combo Is Over $200 Off for Amazon’s Spring Sale

March 25, 2026
This Fire TV Stick Is Already 50% Off for the Amazon Spring Sale
Protection

This Fire TV Stick Is Already 50% Off for the Amazon Spring Sale

March 25, 2026
Load More
Next Post
Dow Jones Slides 250 Points On Key Economic Data; Tesla Stock Downgraded To Sell

Dow Jones Slides 250 Points On Key Economic Data; Tesla Stock Downgraded To Sell

Popular News

  • Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    0 shares
    Share 0 Tweet 0
  • BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

    0 shares
    Share 0 Tweet 0
  • L&G enters $1bn strategic partnership with Enosis Capital

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • US gasoline prices to rise after attack on Iran, analysts warn

    0 shares
    Share 0 Tweet 0

Latest News

These Refurbished AirPods4 (With ANC) Are Just $118 During the Amazon Big Spring Sale

These Refurbished AirPods4 (With ANC) Are Just $118 During the Amazon Big Spring Sale

March 25, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

Bitwise CIO Matt Hougan says Circle could reach $75B by 2030 despite recent selloff

Bitwise CIO Matt Hougan says Circle could reach $75B by 2030 despite recent selloff

March 25, 2026
0

Bitwise CIO Matt Hougan said Circle could reach a valuation of roughly $75 billion by 2030, laying out a long-term...

Here’s how much it could cost to fix Mideast oil and gas production damaged by the Iran war

Here’s how much it could cost to fix Mideast oil and gas production damaged by the Iran war

March 25, 2026
0

The damage to energy infrastructure in the Middle East caused by the war with Iran will take years and billions...

Condé Nast Traveler

How the Iran War is Reconfiguring the World’s Flight Map

March 25, 2026
0

For travelers in North America, Europe and the closer Asia hubs like Japan and Singapore are your likely new connection...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.