Third-party code, Cloud Security
Repojacking attacks against over 15K Go module repositories likely
More than 15,000 Go module repositories on GitHub accounting for at least 800,000 Go module variants could be compromised in repojacking attacks, The Hacker News reports.
Over 9,000 of the repositories were vulnerable as a result of username changes in GiHub, while the remaining repositories were exposed due to account deletion, a report from VulnCheck revealed.
Repojacking attacks are more likely against Go modules due to their decentralized nature, said researchers.
"Anyone can then instruct the Go module mirror and pkg.go.dev to cache the module's details. An attacker can register the newly unused username, duplicate the module repository, and publish a new module to proxy.golang.org and go.pkg.dev," said VulnCheck Chief Technology Officer Jacob Baines.
Baines also noted that Go or GitHub should be responsible for addressing such repojacking attack concerns.
"Until then, it's important for Go developers to be aware of the modules they use, and the state of the repository that the modules originated from," Baines added.
An In-Depth Guide to Cloud Security
Get essential knowledge and practical strategies to fortify your cloud security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds