# Third-party plugin repository hijacked

**URL:** https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703
**Category:** Support
**Created:** [July 17, 2025, 8:37pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703 "2025-07-17T20:37:56Z")
**Posts on this page:** 18
**Page:** 1

<div class="post-metadata">

### Author: ![Roi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roi/32/130587_2.png) [@Roi](https://meta.discourse.org/u/Roi)
#### Post date: [July 17, 2025, 8:37pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/1 "2025-07-17T20:37:56Z")

</div>

Just rebuilt one of my Discourse forums and when I load it in the browser, the following message shows up in a popup:

> You’ve been hacked by a plugin! by w3shi(Hackerone)-S.Lakshmi Vignesh(RCE-POC)

Holy… What is going on? One of the plugins I use was compromised?

---

<div class="post-metadata">

### Author: ![Moin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/moin/32/554653_2.png) [@Moin](https://meta.discourse.org/u/Moin)
#### Post date: [July 17, 2025, 8:53pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/2 "2025-07-17T20:53:33Z")

</div>

Any chance you used the migrate password plugin? Or another plugin from the discoursehosting repository?

> **[You've been hacked](https://www.dolibarr.fr/forum/t/youve-been-hacked/49609/3)**
>
> Bonjour, En effet, cela était en lien avec la dernière mise à jour du forum effectuée ce midi. Cela a depuis été corrigé. Un pseudo chercheur en sécurité à récupéré un ancien dépôt git d’un plugin utilisé par le forum et l’a détourné pour...

Looks like this forum was affected too [Am I hacked? or not - Forum Management - Suggestions - DxO Forum](https://forum.dxo.com/t/am-i-hacked-or-not/50854)

---

<div class="post-metadata">

### Author: ![Roi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roi/32/130587_2.png) [@Roi](https://meta.discourse.org/u/Roi)
#### Post date: [July 17, 2025, 8:59pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/3 "2025-07-17T20:59:05Z")

</div>

> [@Moin](#):
>
> Any chance you used the migrate password plugin? Or another plugin from the discoursehosting repository?

Yes, it’s in the list. And the only one from discoursehosting.

I remember that it needs to be active to allow “old” users to login, correct?

But now the question is more if the installation was compromised or if it’s just showing this message. Site is down at the moment to be safe for now.

Along with that plugin, here’s the list what I’m using:

- [GitHub - discourse/docker\_manager: Plugin for use with discourse docker image · GitHub](https://github.com/discourse/docker_manager.git)
- [GitHub - discourse/discourse-adplugin: Official Discourse Advertising Plugin. Install & Start Serving Ads on Your Discourse Forum · GitHub](https://github.com/discourse/discourse-adplugin.git)
- [GitHub - discourse/discourse-affiliate · GitHub](https://github.com/discourse/discourse-affiliate.git)
- [GitHub - discourse/discourse-ai: Discourse AI now lives in the discourse/discourse repo · GitHub](https://github.com/discourse/discourse-ai.git)
- [GitHub - discourse/discourse-akismet: give spam a whoopin · GitHub](https://github.com/discourse/discourse-akismet.git)
- [GitHub - pfaffman/discourse-allow-pm-to-staff: Allow private messages to be sent to staff for users who could otherwise not send private messages. · GitHub](https://github.com/pfaffman/discourse-allow-pm-to-staff.git)
- [GitHub - discourse/discourse-animated-avatars: A plugin to add gif avatars in Discourse · GitHub](https://github.com/discourse/discourse-animated-avatars.git)
- [GitHub - discourse/discourse-authentication-validations · GitHub](https://github.com/discourse/discourse-authentication-validations.git)
- [GitHub - discourse/discourse-auto-deactivate: This plugin will automatically deactivate stale users so that they need to recomfirm their email in order to login in again · GitHub](https://github.com/discourse/discourse-auto-deactivate.git)
- [GitHub - discourse/discourse-bbcode: vBulletin BBCode plugin · GitHub](https://github.com/discourse/discourse-bbcode.git)
- [GitHub - discourse/discourse-bcc: Allows staff members to send individual PMs to many users at once (like email BCC) · GitHub](https://github.com/discourse/discourse-bcc.git)
- [GitHub - discourse/discourse-cakeday: Show a birthday cake emoji beside the names of members on their join anniversary, or their actual birthday -- and a browsable directory of upcoming anniversaries / birthdays. · GitHub](https://github.com/discourse/discourse-cakeday.git)
- [GitHub - discourse/discourse-characters-required: Display how many characters are required before a post be made · GitHub](https://github.com/discourse/discourse-characters-required.git)
- [GitHub - discourse/discourse-fingerprint: A plugin that computes user fingerprints to help administrators combat internet trolls. · GitHub](https://github.com/discourse/discourse-fingerprint.git)
- [GitHub - discourse/discourse-follow: A Discourse plugin that lets you follow other users. · GitHub](https://github.com/discourse/discourse-follow.git)
- [GitHub - LeoDavidson/discourse-forcemoderation: Discourse plugin to force posts by specified usernames through moderation. · GitHub](https://github.com/leodavidson/discourse-forcemoderation.git)
- [GitHub - discourse/discourse-docs · GitHub](https://github.com/discourse/discourse-knowledge-explorer.git)
- [GitHub - communiteq/discourse-legal-compliance · GitHub](https://github.com/communiteq/discourse-legal-compliance.git)
- [GitHub - merefield/discourse-locations: Tools for handling locations in Discourse · GitHub](https://github.com/angusmcleod/discourse-locations.git)
- [https://github.com/discoursehosting/discourse-migratepassword.git](https://github.com/discoursehosting/discourse-migratepassword.git)
- [GitHub - discourse/discourse-policy · GitHub](https://github.com/discourse/discourse-policy.git)
- [GitHub - paviliondev/discourse-post-badges-plugin · GitHub](https://github.com/paviliondev/discourse-post-badges-plugin.git)
- [GitHub - communiteq/discourse-private-topics · GitHub](https://github.com/communiteq/discourse-private-topics.git)
- [GitHub - discourse/discourse-push-notifications: Plugin for integrating Chrome and FireFox push notifications · GitHub](https://github.com/discourse/discourse-push-notifications.git)
- [GitHub - featheredtoast/discourse-pushover-notifications: Pushover notifications for Discourse · GitHub](https://github.com/featheredtoast/discourse-pushover-notifications.git)
- [GitHub - discourse/discourse-restricted-replies: Plugin to restrict replies in a category to the OP, and members of a specified group · GitHub](https://github.com/discourse/discourse-restricted-replies.git)
- [GitHub - discourse/discourse-saved-searches: Allow users to save searches and be notified of new results. · GitHub](https://github.com/discourse/discourse-saved-searches.git)
- [GitHub - discourse/discourse-shared-edits: Shared edits for Discourse · GitHub](https://github.com/discourse/discourse-shared-edits.git)
- [GitHub - discourse/discourse-signatures: A Discourse Plugin to show user signatures below posts · GitHub](https://github.com/discourse/discourse-signatures.git)
- [GitHub - discourse/discourse-solved: Allow accepted answers on topics · GitHub](https://github.com/discourse/discourse-solved.git)
- [GitHub - discourse/discourse-staff-alias: Allow staff users to post under an alias · GitHub](https://github.com/discourse/discourse-staff-alias.git)
- [GitHub - discourse/discourse-steam-login: Allows user authentication with discourse via the Steam user API · GitHub](https://github.com/discourse/discourse-steam-login.git)
- [GitHub - singerscreations/discourse-stopforumspam · GitHub](https://github.com/singerscreations/discourse-stopforumspam.git)
- [GitHub - discourse/discourse-styleguide: Adds a styleguide to Discourse to aid in styling · GitHub](https://github.com/discourse/discourse-styleguide.git)
- [GitHub - davidtaylorhq/discourse-telegram-notifications: A plugin for Discourse which allows users to receive their notifications by telegram message · GitHub](https://github.com/davidtaylorhq/discourse-telegram-notifications.git)
- [GitHub - discourse/discourse-templates: A plugin that allows users to use templates to insert frequently used content · GitHub](https://github.com/discourse/discourse-templates.git)
- [GitHub - discourse/discourse-tooltips: Show tooltips around Discourse on hover, including topic previews · GitHub](https://github.com/discourse/discourse-tooltips.git)
- [GitHub - jannolii/discourse-topic-trade-buttons · GitHub](https://github.com/jannolii/discourse-topic-trade-buttons.git)
- [GitHub - discourse/discourse-topic-voting: Adds the ability for voting on a topic within a specified category in Discourse. · GitHub](https://github.com/discourse/discourse-topic-voting.git)
- [GitHub - discourse/discourse-translator · GitHub](https://github.com/discourse/discourse-translator.git)
- [GitHub - discourse/discourse-user-field-prompt · GitHub](https://github.com/discourse/discourse-user-field-prompt.git)
- [GitHub - communiteq/discourse-user-response-times · GitHub](https://github.com/communiteq/discourse-user-response-times.git)
- [GitHub - discourse/discourse-whos-online: A plugin for Discourse which uses the messagebus to display a live list of active users · GitHub](https://github.com/discourse/discourse-whos-online.git)
- [GitHub - discourse/discourse-yearly-review: Publishes an automated Year in Review topic · GitHub](https://github.com/discourse/discourse-yearly-review.git)

---

<div class="post-metadata">

### Author: ![Lilly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lilly/32/575047_2.png) [@Lilly](https://meta.discourse.org/u/Lilly)
#### Post date: [July 17, 2025, 9:04pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/4 "2025-07-17T21:04:16Z")

</div>

just remove anything referring to `discoursehosting`

---

<div class="post-metadata">

### Author: ![Roi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roi/32/130587_2.png) [@Roi](https://meta.discourse.org/u/Roi)
#### Post date: [July 17, 2025, 9:04pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/5 "2025-07-17T21:04:35Z")

</div>

Google Translate of the French forum post:

> A pseudo-security researcher retrieved an old Git repository for a plugin used by the forum and hijacked it to simply display this message.
> 
> The repository in question (GitHub - discoursehosting/discourse-migratepassword: A touch of security) has been inspected and no malicious code is present (it’s simply a proof of concept).
> 
> This repository had actually changed its URL (it is now available at GitHub - communiteq/discourse-migratepassword: Support migrated password hashes) and the user simply recreated the discoursehosting/discourse-migratepassword repository, which previously redirected to communiteq/discourse-migratepassword, to place unrelated code there. We were using the old URL, which is why we were affected.

If that’s true, okay… I changed the url of the plugin to communiteq and am rebuilding at the moment. But I have to look into this more (as I am not a programmer, I can’t be 100% sure).

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [July 17, 2025, 9:27pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/6 "2025-07-17T21:27:19Z")

</div>

## TL;DR

This is a Github vulnerability in an exploit class called “Repojacking”.

We recommend everyone to check their Github plugin URLs and rename each and every instance of `discoursehosting` to `communiteq`

## Background:

We had to rename our company from Discoursehosting to Communiteq in 2019.  
If that happens, Github automatically redirects URLs to github repositories to their new location, **until** someone creates a repository with the same name. At that moment the new repository will take preference.

Github used to mark such repositories as “retired” and prohibited creating a repository with the same name.

A previous exploit is described [here](https://checkmarx.com/blog/persistent-threat-new-exploit-puts-thousands-of-github-repositories-and-millions-of-users-at-risk/?utm_source=chatgpt.com). Apparently that fix is no longer effective.

We have filed a Github abuse report and will try to take this repository down with all available means.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [July 17, 2025, 9:33pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/7 "2025-07-17T21:33:55Z")

</div>

> [@Roi](#):
>
> But now the question is more if the installation was compromised or if it’s just showing this message

At this moment the compromised plugin only shows a message and leaves a harmless file in /tmp.  
So nothing bad has happened - yet. It is important to change your plugin URL before you rebuild.

---

<div class="post-metadata">

### Author: ![Ethsim2](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ethsim2/32/522255_2.png) [@Ethsim2](https://meta.discourse.org/u/Ethsim2)
#### Post date: [July 17, 2025, 9:44pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/8 "2025-07-17T21:44:05Z")

</div>

> [@RGJ](#):
>
> Repojacking

wow it can catch the end user out easily, one of the main disadvantages of not using [discourse.org](http://discourse.org) official hosting.

If either

[angusmcleod (Angus McLeod) · GitHub](https://github.com/angusmcleod) or [merefield (Robert) · GitHub](https://github.com/merefield)

accounts ceased to exist

then a first sub-path would be exposed, so there would be a clone command sitting in my app.yml for a rebuild to execute

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [July 17, 2025, 10:25pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/9 "2025-07-17T22:25:19Z")

</div>

To mitigate the potential impact for users of the [standard install](https://meta.discourse.org/t/142537?silent=true), we’ve added code to detect `github.com/discoursehosting/` and abort any rebuilds/upgrades.

- [Fail rebuild for config files containing compromised github organisat… · discourse/discourse\_docker@7889fe3 · GitHub](https://github.com/discourse/discourse_docker/commit/7889fe39ebc749c203cc892e29f7e90eddcf07c6)

- [Fail rebuild for config files containing compromised github organisat… · discourse/docker\_manager@f568625 · GitHub](https://github.com/discourse/docker_manager/commit/f5686257e7bb4bdd60bb745d796c9ed9e9b735f2)

The error will look something like

```plaintext
---
ERROR: The configuration file containers/app.yml contains references to a compromised github organization: github.com/discoursehosting
Please remove any references to this organization from your configuration file.
For more information, see https://meta.discourse.org/t/374703/6
---

```

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [July 17, 2025, 10:49pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/10 "2025-07-17T22:49:47Z")

</div>

![](https://media.tenor.com/4jLOP7ietGkAAAAC/awesome-youre-awesome.gif)

Thank you David!

---

<div class="post-metadata">

### Author: ![w3shi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/w3shi/32/513802_2.png) [@w3shi](https://meta.discourse.org/u/w3shi)
#### Post date: [July 22, 2025, 2:50am UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/11 "2025-07-22T02:50:52Z")

</div>

Hello Discourse community,

I want to sincerely apologize for the disruption caused by my actions regarding the plugin repository. In attempting to highlight a security issue, I made serious mistakes that violated the code of conduct.

Going forward, I will ensure my actions adhere to responsible disclosure practices and I appreciate the opportunity to learn from this.

Again, I am truly sorry for the disruption caused.

@w3shi

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [July 22, 2025, 5:58am UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/12 "2025-07-22T05:58:25Z")

</div>

Thank you for your apologies.

The next not-so responsible thing was not reaching out to me or CDCK privately when you gave up the handle, because in the past three hours, someone else could have seen your post and registered it.

I have now regained control over the old Github handle. And thank you for doing the right thing eventually, and for pointing out that Github does not protect redirects anymore for the **fifth** time (last time was the fourth time: [“This discovery marks the fourth time an alternate method has been identified for performing Repojacking”](https://checkmarx.com/blog/persistent-threat-new-exploit-puts-thousands-of-github-repositories-and-millions-of-users-at-risk/))

I suggest you approach Github and collect your bounty!

---

<div class="post-metadata">

### Author: ![w3shi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/w3shi/32/513802_2.png) [@w3shi](https://meta.discourse.org/u/w3shi)
#### Post date: [July 22, 2025, 6:14am UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/13 "2025-07-22T06:14:18Z")

</div>

I Sincerely apologize for all the inconvenience caused! And Thank you for your understanding @RGJ !.

---

<div class="post-metadata">

### Author: ![schleifer](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/schleifer/32/86416_2.png) [@schleifer](https://meta.discourse.org/u/schleifer)
#### Post date: [July 22, 2025, 2:40pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/14 "2025-07-22T14:40:34Z")

</div>

Welcome to the community and thank you for fixing everything up.

---

<div class="post-metadata">

### Author: ![elmuerte](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elmuerte/32/456517_2.png) [@elmuerte](https://meta.discourse.org/u/elmuerte)
#### Post date: [July 22, 2025, 3:51pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/16 "2025-07-22T15:51:41Z")

</div>

You should basically assume that nothing is safe, which doesn’t work well either.

Just a few days ago it came to light that one of the developers behind some ESLint Prettier package’s NPM account was compromised and they published new compromised versions of some popular packages:

> **[Maintainers of ESLint Prettier Plugin Attacked via npm Supply Chain Malware |...](https://snyk.io/blog/maintainers-of-eslint-prettier-plugin-attacked-via-npm-supply-chain-malware/)**
>
> Urgent warning: Maintainers of popular npm packages like ESLint Prettier Plugin were attacked via an npm supply chain malware incident. Learn about the typosquatting, phishing, and impacted packages, plus essential steps to protect your projects.

These packages were then referenced in other packages, because many claim that you should always update to the latest versions.

After I saw this thread I suggested a feature to introduce signature validation of plugins/theme components while updating them: [Plugin and theme component signing](https://meta.discourse.org/t/plugin-and-theme-component-signing/374817)

That would not stop a compromised key, but at least make _part_ of the supply chain more trustworthy. In the end it is still possible that compromised third party libraries are pulled in. Additional dependencies are not really visible.

---

<div class="post-metadata">

### Author: ![LeoDavidson](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/leodavidson/32/119574_2.png) [@LeoDavidson](https://meta.discourse.org/u/LeoDavidson)
#### Post date: [August 19, 2025, 1:28pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/17 "2025-08-19T13:28:10Z")

</div>

> [@david](#):
>
> To mitigate the potential impact for users of the [standard install](https://meta.discourse.org/t/142537?silent=true), we’ve added code to detect `github.com/discoursehosting/` and abort any rebuilds/upgrades.

I’m not sure this still works. I had a plugin pointing to the compromised github URL and the error message during rebuild just said it failed to pull the repository, with some further detail about a gem version or something. (Can’t paste the exact info as it’s too far back in my scrollback from all the other noise during subsequent builds.)

Looks like the URL/repository doesn’t exist at all now, which is good (at least until someone else re-creates it) but the error message would’ve saved a lot of time.

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [August 19, 2025, 1:32pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/18 "2025-08-19T13:32:32Z")

</div>

Indeed, @RGJ is now back in control of the github organization, so we’ve removed the temporary error message.

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [September 23, 2025, 11:59pm UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/19 "2025-09-23T23:59:52Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
