Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Repojacking can put software at risk when a GitHub username or organization changes its name, the old name becomes available, and someone else claims it. A dependency that still points to the old GitHub path may then retrieve attacker-controlled code. The exposure is real, especially for dependencies fetched directly from GitHub, but the available evidence does not establish an audited count of thousands of vulnerable packages.

What repo-jacking is and how it works

Repojacking targets a mutable address: the combination of a GitHub owner name and repository name. It is not, by itself, an attack on a package registry or a way to break a cryptographic commit hash.

  1. A GitHub user or organization renames its account. GitHub redirects requests made to the old name to the renamed account.
  2. The former name is later released and can be claimed by another user.
  3. The attacker creates a repository using the old repository name. A request to the former owner/repository path can now reach the replacement repository rather than the original project.

Snyk Security Labs describes this risk as a consequence of allowing owner renames while redirecting old URLs. GitHub describes the same sequence in its account of repo-jacking. The key failure is relying on a name that can be reassigned instead of verifying that the code comes from the intended repository and revision.

Which dependencies are most exposed

The clearest risk is a build or runtime workflow that fetches source directly from a GitHub path. If that path is reclaimed, the build may pull different code than its maintainers intended.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • GitHub Actions: A workflow reference such as uses: actions/javascript-action@v1.0.1 names a repository and a version-like reference. Review the reference and, where practical, pin it to a full commit ID.
  • Go modules: Go imports can use GitHub paths directly, so a module path that resolves through a reclaimed owner/repository name may be exposed.
  • Git submodules: A submodule records a commit, which helps identify the checked-out revision, but teams should review the repository URL and commit whenever they update a submodule.
  • Build scripts and other Git clients: Scripts that clone or download a GitHub repository by name can inherit the same namespace risk.

GitHub says its tombstoning policy permanently retires many renamed owner/repository combinations once they meet usage thresholds. That reduces the likelihood of reclaiming high-usage names, but does not remove the risk for every repository; lower-usage paths may remain exposed.

Why this is not usually an npm or PyPI publishing attack

Repojacking a GitHub path does not normally grant permission to publish a new npm or PyPI release. Those registries generally require separate maintainer authentication. A malicious package uploaded through a compromised maintainer account is a serious supply-chain attack, but it is a different mechanism from reclaiming a GitHub namespace.

There has been a historical registry amplification case: GitHub records a May 2022 hautelook/phpass incident involving Packagist, which had crawled GitHub for releases. GitHub says Packagist was updated to remove that amplification path. This should not be read as evidence that repojacking can generally publish to npm or PyPI.

How many packages are actually vulnerable?

No authoritative source cited here publishes a verified current total matching the claim “thousands of code packages vulnerable to repo-jacking.” The evidence supports broad exposure and potentially high impact, not a single audited package count.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Snyk Security Labs, 2024: reported that components with tens of millions of downloads could potentially be exposed across the Terraform and Composer ecosystems. Snyk also cautioned that repojacking is under-researched and often confused with typosquatting or account takeover. Potential exposure is not the same as confirmed compromise or a count of vulnerable packages.
  • Sonatype, 2024: reported more than 778,500 malicious open-source packages since 2019, and said that 98.5% of malicious packages observed in its 2024 analysis were in npm. Those are broad malicious-package statistics, not repojacking counts.
  • Sonatype, 2024: also reported a 32.8% year-over-year increase in shadow downloads and more than 450,000 malware attacks blocked for its customers in 2024. Neither figure measures repojacking incidents or vulnerable packages.

These figures describe different populations and outcomes. They cannot be combined into a repojacking package total, and “potentially exposed,” “malicious package,” “download,” and “attack blocked” are not interchangeable measures.

How to reduce repo-jacking risk

1. Pin direct GitHub dependencies to commits

For a direct GitHub dependency, a full commit ID fixes the requested revision instead of trusting a mutable branch or tag name. GitHub calls commit pinning the simplest protection for dependencies downloaded directly from GitHub. For example:

uses: actions/javascript-action@4be183afbd08ddadedcf09f17e8e112326894107

Apply the same principle to other direct Git references where the tooling supports it. A commit pin limits the attacker’s ability to substitute code merely by taking over a name or moving a reference. It does not replace review of the code or a safe process for intentionally updating the pinned revision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Verify repository identity as well as its name

GitHub’s numeric repository ID remains stable when a repository is renamed, but a replacement repository has a different ID. A CI check can query the repository through GitHub’s API and compare both the expected numeric ID and expected full name, failing the build if either differs unexpectedly. The name check catches an unexpected rename; the ID check helps distinguish the original repository from a replacement at the same path.

3. Inventory direct GitHub references

Search the places where your build obtains source, not only the package-manager manifest. Include workflow uses: entries, Go module paths, submodule URLs, Git URLs in build files, and scripts that clone repositories. Give these direct references stronger review and pinning controls than ordinary registry dependencies.

4. Check malware advisories and add supply-chain controls

The GitHub Advisory Database supports the type:malware qualifier, along with filters for ecosystem, severity, date, affected library, and related criteria. Use it to find known malicious packages relevant to the dependencies you consume; advisory searches are a detection aid, not proof that an unlisted dependency is safe.

For broader coverage, software-supply-chain controls can include repository-firewall policies that block known malicious components before ingestion, dependency controls, and software bills of materials (SBOMs) to improve inventory and response. Sonatype describes these as part of managing malicious open-source consumption. They complement direct-GitHub identity checks rather than replacing them.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep repojacking distinct from other supply-chain threats

Repojacking is specifically about reclaiming a former GitHub owner/repository namespace and redirecting a direct source retrieval. Typosquatting uses a lookalike name; account takeover abuses a legitimate maintainer’s credentials; registry malware is published to a package registry. These threats can all deliver malicious code, but they require different checks. Pinning direct Git references and verifying repository identity address repojacking, while registry authentication, advisory monitoring, and malware controls address other routes.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.