The Go programming language’s modules are particularly susceptible to repojacking, distinguishing them from other package manager solutions like npm or PyPI.

#Cybersecurity #GitHub #GoModules #Hijacking #Repojacking

https://cybersec84.wordpress.com/2023/12/06/15000-github-repositories-at-risk-protect-your-go-modules-from-repojacking/

15,000 GitHub Repositories at Risk: Protect Your Go Modules from Repojacking

Recent research has identified a concerning security issue affecting over 15,000 Go module repositories on GitHub, making them susceptible to an attack known as “repojacking.” Jacob Bai…

CyberSec84 | Cybersecurity news.
VulnCheck reports over 9,000 GitHub repositories at risk of repojacking from username changes, plus 6,000+ due to account deletions.In total, 15,000 repositories, supporting 800,000+ Go module-versions, are exposed to this vulnerability. https://vulncheck.com/blog/go-repojacking #GitHubSecurity #Repojacking
Hijackable Go Module Repositories - Blog - VulnCheck

VulnCheck scans the Go module ecosystem for module repositories affected by repojacking, and discover hundreds of thousands of affected module-versions.

VulnCheck
A new Repojacking attack exposed over 4,000 GitHub repositories to hack

A critical vulnerability in GitHub could have exposed more than 4,000 code packages to Repojacking attack.

Security Affairs
Mii de depozite de pe GitHub vulnerabile la RepoJacking – OneTechNews

RepoJacking este o tehnică de atac care exploatează faptul că multe depozite de pe GitHub folosesc fișiere de configurare externe pentru a gestiona dependențele și fluxurile de lucru. Un atacator poate modifica aceste fișiere și introduce cod rău intenționat în proiectele afectate, compromițând astfel securitatea și integritatea lor. Aqua Security, o companie specializată în securitatea

OneTechNews – The Best Site
Security: RepoJacking auf GitHub betrifft auch große Firmen wie Google

Durch die Übernahme von Repositories hinter umbenannten Organisationen auf GitHub können Angreifer Schadcode verbreiten.

heise online
More than a million GitHub repositories potentially vulnerable to RepoJacking

Researchers reported that millions of GitHub repositories are likely vulnerable to an attack called RepoJacking. A study conducted by Aqua researchers revealed that millions of GitHub repositories are potentially vulnerable to RepoJacking. In the RepoJacking attack, attackers claim the old username of a repository after the legitimate creator changed the username, then publish a rogue repository […]

Security Affairs
Hijacking Arch Linux Packages by Repo Jacking GitHub Repositories

Last year, we published a blog post discussing an attack where a malicious actor hijacks Arch User Repository (AUR) vulnerable packages by registering expired domains.

Blog by Joren Vrancken
GitHub: Umbenannte Konten gefährden Tausende von Projekten

Dass GitHub bei der Lösung gegen RepoJacking-Angriffe mehrere Anläufe brauchte, erweckt nicht gerade Vertrauen. Eine Restgefahr bleibt.

Tarnkappe.info