Facebook Twitter Instagram
    Trending
    • JOYROOM PODIX 140W GaN Charger – Desktop Power Station for Modern Tech Setup
    • Mukiya Foldable 3-in-1 Magnetic Wireless Charging Station. One Stand, Total Apple Power!
    • Mukiya USB-C Laptop Docking Station Stand – 8-in-1 Productivity Hub with Built-In Ergonomics
    • BlitzWolf HL7 SmartWatch Now Available on Banggood at Just $39.99
    • FEXO 45000 vs Al Fakher Crown Bar: Which is Best for DTL Vaping?
    • Geek Bar CLR 50K Disposable Vape: A Comprehensive Review for Vaping Enthusiasts
    • New renderings of Google Pixel 10a smartphone unveiled: The raspberry color is eye-catching. The European version has a battery life of 53 hours and 14 minutes.
    • The detailed specifications of Nothing Phone (4a)/Pro have been revealed. The model offers the option of up to 12GB of RAM and 256GB of storage space.
    Facebook YouTube
    Login Register
    IGeeKphone China Phone, Tablet PC, VR, RC Drone News, Reviews
    • HOME
      • NEWS
        • DeepSeek
        • ChatGPT
        • Minecraft
    • Amazon
    • NEW YEAR
    • PHONE
      • Top Phones For Your First Choice
      • Phone Comparison
      • Xiaomi
      • Blackview
      • Doogee
      • Black Shark
      • Geekbuying
      • Banggood
      • TEMU
      • TikTok
      • Aliexpress
      • Walmart
      • MercadoLibre
      • Lazada
    • TOP VAPE Awards for 2026
    • VAPES
      • E-CIGAR Upcoming
      • Vape News
      • Vape Deals
      • Vape Comparison
      • Vape Guide
      • Giveaway
    • BEST VAPE
      • Best Vape Stores
      • Best Starter Vape Kits
      • Best Vapes for Beginners
      • Best Disposable Vapes
      • Best Pod Systems
      • Best Pod Mod Vapes
      • Best Mods
      • Best Nicotine Pouches
      • Best Clearomizers/Tanks
      • Best E-Liquid
      • Best EGO/Pens
      • Best Vapes for Nic Salt E-Juice
      • Best Vapes to Quit Smoking
      • RDA vs. RDTA vs. RTA
    • Best Vape Brand 2026
      • VAPORESSO
      • VOOPOO
      • OXVA
      • NEXA BAR
      • ORIONBARTECH
      • MASKKING VAPE
      • MEMERS
      • SP2S
      • JNR
      • TODOO
      • MRFOG
      • VEIIK
    • REVIEW
      • E-cigar Review
      • Phones
      • Tablet PC
      • TV Box
      • RC Drone
      • Wearables
      • Camera
      • Accessories
      • VR Headset
    • MORE
      • TABLET
        • Chuwi
        • INNOCN
        • Teclast
        • Top Tablet for Your First Choice
        • Tablet/Laptop Comparison
      • RC DRONE
      • CAMERA
      • WEARABLES
        • OneOdio
        • BlitzWolf
        • Top Smartwatch for First Choice
      • 3D PRINTER
        • 3D Printer Review
        • Anycubic
        • FLSUN
        • Xtool
        • LONGER
        • Top 3D printer to Choose First
      • POWER STATION
        • Oukitel
        • FOSSIBOT
      • GAMING
        • Top Gaming Products
      • E-BIKE
        • Samebike
        • Happyrun
        • ENGWE
      • SMART HOME
      • TV BOX
      • ACCESSORIES
      • VR HEADSET
      • CLOTHES
      • AUTO CAR
    • DEAL
    • Shop
    IGeeKphone China Phone, Tablet PC, VR, RC Drone News, Reviews
    You are at:Home»ChatGPT»Researchers have discovered a RepoJacking vulnerability on GitHub that allows user libraries to be hijacked
    ChatGPT

    Researchers have discovered a RepoJacking vulnerability on GitHub that allows user libraries to be hijacked

    Brady CottonBy Brady CottonJune 27, 2023
    Facebook Twitter Pinterest LinkedIn Tumblr Email

    Security company Aqua Nautilus has exposed the RepoJacking vulnerability in GitHub libraries, which can be used by hackers to break into GitHub’s private or public libraries and replace files in these organizations’ internal environments or customer environments with versions of malicious code to carry out hijacking attacks.

    RepoJacking, which can occur when a GitHub user/organization changes its name, is a supply chain attack that allows an attacker to take over dependencies or entire projects of GitHub projects to run malicious code against any device that uses those projects.

    Hackers can directly scan the Internet, lock the GitHub library that needs to be attacked, and bypass the GitHub repository restrictions, replace the file with a version with a Trojan virus, and after other users download and deploy, hackers can manipulate the user terminal and carry out attacks.

    Aqua Nautilus uses Lyft for a demonstration, they create a fake repository, and get the script redirected, users using the install.sh script will unknowingly install Lyft with malicious code on their own, as of press time, Lyft’s vulnerability has been fixed.

    The researchers also found related vulnerabilities in Google’s libraries on GitHub:

    When users visit https://github.com/socraticorg/mathsteps, will be redirected to https://github.com/google/mathsteps so that the end user, Google will be given to the repository. However, because the socraticorg organization is available, the attacker can open the socraticorg/mathsteps repository and the user, if he executes the installation command given by Google directly in the terminal, will actually download the malicious files replaced by the hacker.

    After feedback from Aqua Nautilus, Google has now fixed the issue.

    Aqua Nautilus says that users can circumvent the RepoJacking vulnerability by creating a link between the old name of the GitHub library and the new name (redirecting the old name to the new name), which can be found here for more information.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    New renderings of Google Pixel 10a smartphone unveiled: The raspberry color is eye-catching. The European version has a battery life of 53 hours and 14 minutes.

    The detailed specifications of Nothing Phone (4a)/Pro have been revealed. The model offers the option of up to 12GB of RAM and 256GB of storage space.

    Rendering images of Apple iPhone 17e have been released: featuring the A19 chip, a 48-megapixel single camera, and supporting MagSafe technology

    Leave A Reply Cancel Reply

    You must be logged in to post a comment.

    voopoo Cyph NAVI kit
    oxva xlim 3 ultra
    sp2s sen x disposable vape
    jnr 100k
    • Popular
    • 3D Printer REVIEW
    • XIAOMI
    February 8, 2026

    VOOPOO VMATE i2 vs i3: Hands-On Comparison Review

    February 2, 2026

    Voopoo Drag X3 vs Drag X2: Hands-On Comparison Review

    January 21, 2026

    VOOPOO ARGUS P3 VS ARGUS P2: Which Square Pod Suits You?

    January 21, 2026

    VOOPOO Drag X3 vs VOOPOO Drag X2: Hands-On Comparison

    December 26, 2025

    ACMER ASCARVA 4S: Precision CNC Power for Makers, DIYers & Small Workshops

    June 23, 2024

    ACMER P2 20W Laser Engraver Fixed Focus Engraving: Hands on Review

    May 30, 2024

    xTool F1 Ultra Review: World’s First 20W Fiber & 20W Diode Laser Engraver

    May 30, 2024

    Anycubic Kobra 3 Combo Review: The Multicolor Masterpiece?

    February 9, 2026

    Xiaomi 18 is the world’s first! The cost of Qualcomm Snapdragon 8 Elite Gen 6 Pro is outrageously high

    February 6, 2026

    Xiaomi 17 Ultra will make its debut at MWC: The battery capacity of the international version has been reduced to 6000mAh.

    February 4, 2026

    Xiaomi Hyper OS 4 undergoes a major upgrade: Completely eliminates old code and boosts smoothness.

    February 2, 2026

    The new 6.59-inch mid-to-high-end model of a Certain factory is tentatively scheduled to be released in the first half of this year. It is expected to be under the brand of Xiaomi.

    fc 26 coins
    New Arrivals
    • Geek Bar CLR 50K Disposable Vape Geek Bar CLR 50K Disposable Vape
    • Redmi Turbo 5 Max Redmi Turbo 5 Max
    • OnePlus Turbo 7 OnePlus Turbo 7
    • Doogee S300 Ultra Doogee S300 Ultra
    • iQOO 15R iQOO 15R
    • VOOPOO NAVI X Cyph 80K Disposable Vape Kit VOOPOO NAVI X Cyph 80K Disposable Vape Kit
    • OXVA Slim Stick X Vape OXVA Slim Stick X Vape
    • Geek Bar Somax 80K Disposable Vape Geek Bar Somax 80K Disposable Vape
    • Geek Bar Clio Platinum 50K Disposable Vape Kit Geek Bar Clio Platinum 50K Disposable Vape Kit
    About
  • Igeekphone.com provides the first global tech news and reviews about smartphone, vapes, e-cigar, smart home, 3D printers, e-bike,tablets, RC drones, VR headset, and other accessories. It's the best platform to improve your brand and product.
  • Contact us: info@igeekphone.com
  • Check Our Privacy Policy Here.
  • Note: *Right now we have US editor and EU editors for review, especially for Amazon US and EU.
  • *Shop and Compare Price Here*
  • Facebook
  • Youtube
  • OUR BEST VAPE PARTNERS
  • VAPE ONLINE STORE
  • HAYATI PRO MAX PLUS
  • VAPORESSO
  • VOOPOO
  • OXVA
  • NEXA
  • MASKKING
  • LOSTVAPE ORIONBAR
  • MEMERS
  • TODOO
  • SP2S
  • JNR
  • VEIIK
  • OTHER BEST PARTNERS
  • SVBONY
  • Chuwi
  • Blackview
  • Fossibot
  • Unihertz
  • Flsun
  • Anycubic
  • Xtool
  • Oukitel
  • Mukkpet Ebike
  • Ugreen
  • Copyright © 2026 igeekphone

    Type above and press Enter to search. Press Esc to cancel.