Attacking the Software Supply Chain with a Simple Rename

If not explicitly tended, all renamed usernames on GitHub were vulnerable to this flaw, including over 10,000 packages on the Go, Swift, and Packagist package managers. This means that thousands of packages could have been hijacked immediately and start serving malicious code to millions of users. The vulnerability was fixed by GitHub following our report … Continue reading Attacking the Software Supply Chain with a Simple Rename