Malicious Domain ghrc.io Impersonates GitHub Container Registry to Steal Credentials
By
todsacerdoti
Crispy enough to crunch, soft enough to enjoy. A good bake.
Summary
A malicious domain ghrc.io is impersonating GitHub's legitimate container registry ghcr.io to steal GitHub credentials. The domain appears to be a simple typo of the legitimate ghcr.io address but is actually running a default nginx setup that is maliciously capturing user credentials when developers accidentally type the wrong address.
Key quotes
· 4 pulledA simple typo of ghcr.io to ghrc.io would normally be a small goof
But in this case, that typo appears to be doing something very malicious, stealing GitHub credentials
ghcr.io is an OCI conformant registry for container images and OCI artifacts used by a lot of projects
ghrc.io Is Just a Default Nginx
You might also wanna read
Security Researcher Finds 16 Vulnerabilities in Lovable-Hosted App Exposing 18,000 Users' Data
A security researcher discovered 16 vulnerabilities, including 6 critical ones, in a Lovable-hosted application that exposed data of over 18
Prompt Injection Attacks: The Top Security Threat Hijacking AI Chatbots
Prompt injection attacks are a critical security vulnerability in AI systems where hidden instructions within user data (like emails or docu
Quantum computing's security threats demand urgent preparation from IT professionals
The article discusses the impending quantum computing revolution and its dual nature: promising transformative advances while simultaneously
zdnet.com·11h agoCISA warns security teams of wave of attacks targeting software supply chain credentials
CISA has issued a warning urging security teams to check for software development compromises, specifically regarding a wave of attacks targ
Security Researchers Expose Weak Encryption in Canon Enterprise Printers
During a network security assessment, security researchers discovered that Canon enterprise printers configured with default administrator c
securityboulevard.com·1d agoNew browser-based side-channel attack uses SSD activity analysis to spy on users
Researchers have discovered a new browser-based side-channel attack that can spy on users by analyzing SSD (Solid State Drive) activity thro
arstechnica.com·1d ago