Web Hack List

Collected research

Repo Jacking: Exploiting the Dependency Supply Chain

Measures repository-namespace reuse across 2.8 million GitHub projects and a dependency graph, identifying direct and transitive packages that can be redirected to an attacker-controlled repository. It also covers vulnerable script and submodule references and proposes detection and mitigation steps.

Record

Researcher
Indiana Moreau
Published by
Security Innovation

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Indiana Moreau, first published at the original source. Preserved copies are kept so the citation survives its host.