Threat actors are actively scanning public repositories for privately configured GitLab email addresses, using them to push malicious code directly into projects.

Security researchers have observed that these special email addresses, often documented in READMEs and contribution guides to help users file issues, are being weaponized. By sending crafted emails to these addresses, an attacker can bypass normal authentication, potentially forcing unauthorized commits or changes to a repository's source code. This turns a convenience feature for community interaction into a potent supply-chain attack vector.

The vulnerability exploits a fundamental misunderstanding of GitLab's functionality. Projects that publicly list these email addresses for bug reports or task management inadvertently hand attackers a direct line to inject code, affecting all downstream users and applications that depend on the compromised project.

Unlike traditional software bugs, attackers are not exploiting a flaw in GitLab itself but rather a widespread and commonly recommended practice. Security experts warn that any publicly listed push-email address should be considered compromised, urging teams to audit their repositories, rotate exposed credentials, and disable the feature where it is not essential to their workflow.

The incident underscores a recurring theme in software security: features built for collaboration can become liabilities when their operational mechanics are not fully understood. As open-source supply chains grow more interconnected, proactive management of repository configuration details has become a critical component of maintaining code integrity.


威脅行為者正主動掃描公開儲存庫,尋找私有設定的 GitLab 電郵地址,並利用這些地址直接將惡意代碼推送至專案中。

安全研究人員觀察到,這些特殊電郵地址(通常記載於 README 檔案及貢獻指南中,旨在協助用戶提交問題)正被武器化。攻擊者透過向這些地址發送特製電郵,可繞過正常認證機制,強制進行未經授權的提交或修改儲存庫原始碼。這將原本用於社區互動的便利功能,轉變為強大的供應鏈攻擊向量。

此漏洞源於對 GitLab 功能的根本性誤解。公開列出這些電郵地址用於錯誤報告或任務管理的專案,無意間為攻擊者提供了注入代碼的直接途徑,影響所有依賴該受損專案的下游用戶與應用程式。

與傳統的軟件漏洞不同,攻擊者並非利用 GitLab 本身的缺陷,而是利用一種廣泛存在且常被推薦的做法。安全專家警告,任何公開列出的推送電郵地址均應被視為已被入侵,敦促團隊審計其儲存庫、更換已暴露的憑證,並在工作流程非必需時禁用此功能。

此事件凸顯了軟件安全中一個反覆出現的主題:專為協作設計的功能,若其操作機制未被完全理解,可能會成為負擔。隨著開源供應鏈變得更加互聯互通,主動管理儲存庫配置細節已成為維護代碼完整性的關鍵組成部分。

新聞來源 / Original News Source