Spoofing commits as a trusted Identity, as easy as 1-2-3
We reported recently on an attacker who spoofed commits appearing to be from Dependabot ( / dependabot-contributes-malicious-code .
How difficult is it to perform such an attack?
What are the steps involved?
How can developers detect such attacks?
Does this affect just Dependabot?
This video will answer all these questions.
Link to the tool used in video: https://github.com/GuyNachshon/trustB...
You can read more about this and much more, on our medium platform: / checkmarx
You can also find us on twitter at @Cx_SCS
Checkmarx Supply Chain Security
Working to Keep the Open Source Ecosystem Safe