Repo Jacking: How GitHub exposes over 70,000 projects to remote code injection

No ratings

Presented at BSidesLV 2021 by

Does your project depend on a GitHub repository? It might be vulnerable to remote code injection. This talk will discuss ‘repo jacking’, an obscure supply chain vulnerability that allows attackers to hijack GitHub repositories and achieve remote code execution. This vulnerability has become exceedingly widespread in open-source projects and over 70,000 projects are affected, including popular projects from organizations such as Google, Facebook, Microsoft, and many more. Repo jacking can affect any language and has been found to impact small personal games, huge web frameworks, cryptocurrency wallets, and everything in between.