Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-692 — Spoof Version Control System Commit Metadata
CAPEC-692

Spoof Version Control System Commit Metadata

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Medium. An adversary spoofs metadata pertaining to a Version Control System (VCS) (e.g., Git) repository's commits to deceive users into believing that the maliciously provided software is frequently maintained and originates from a trusted source.

Mitigation

Before downloading open-source software, perform precursory metadata checks to determine the author(s), frequency of updates, when the software was last updated, and if the software is widely leveraged. | Reference vulnerability databases to determine if the software contains known vulnerabilities. | Only download open-source software from reputable hosting sites or package managers. | Only download open-source software that has been adequately signed by the developer(s). For repository commits/tags, look for the "Verified" status and for developers leveraging "Vigilant Mode" (GitHub) or similar modes. | After downloading open-source software, ensure integrity values have not changed.

Details

Platforms
Social-engineering
Supply-chain
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.