# 서드파티 플러그인 저장소 탈취

**URL:** https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703
**Category:** Support
**Created:** [7월 17, 2025, 8:37오후 UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703 "2025-07-17T20:37:56Z")
**Posts on this page:** 1
**Showing post:** 6

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [7월 17, 2025, 9:27오후 UTC](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703/6 "2025-07-17T21:27:19Z")

</div>

## 요약

이것은 "Repojacking"이라는 익스플로잇 클래스에 해당하는 GitHub 취약점입니다.

모든 사용자에게 GitHub 플러그인 URL을 확인하고, `discoursehosting`의 모든 인스턴스를 `communiteq`으로 이름 변경할 것을 권장합니다.

## 배경:

우리는 2019년에 회사명을 Discoursehosting에서 Communiteq으로 변경해야 했습니다.  
이런 상황이 발생하면, GitHub은 저장소 URL을 자동으로 새 위치로 리디렉션합니다. **다만** 누군가 동일한 이름의 저장소를 생성하는 순간까지는요. 그 시점에 새로운 저장소가 우선권을 갖게 됩니다.

GitHub은 과거에 이러한 저장소를 “retired”(폐쇄됨)로 표시하고 동일한 이름의 저장소 생성을 금지했습니다.

이전 익스플로잇에 대한 설명은 [여기](https://checkmarx.com/blog/persistent-threat-new-exploit-puts-thousands-of-github-repositories-and-millions-of-users-at-risk/?utm_source=chatgpt.com)에 있습니다. 그런데 Apparently 해당 수정안이 더 이상 유효하지 않은 것으로 보입니다.

우리는 GitHub 악용 신고를 접수했으며, 모든 가용한 수단을 동원하여 이 저장소를 삭제하는 데 노력할 것입니다.

---

_[View the full topic](https://meta.discourse.org/t/third-party-plugin-repository-hijacked/374703)._
