Collected research
Repo Jacking: Exploiting the Dependency Supply Chain
Measures repository-namespace reuse across 2.8 million GitHub projects and a dependency graph, identifying direct and transitive packages that can be redirected to an attacker-controlled repository. It also covers vulnerable script and submodule references and proposes detection and mitigation steps.
Record
- Researcher
- Indiana Moreau
- Published by
- Security Innovation
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Indiana Moreau, first published at the original source. Preserved copies are kept so the citation survives its host.