ADVERTISEMENT

One-fifth of Docker Hub repositories are malicious, researchers find

Nearly three million repositories on Docker Hub, a platform for web developers to collaborate on their code for web applications, contain malicious content, security researchers at JFrog have found.

docker

Images by Shutterstock.

Ernestas Naprys
Ernestas Naprys Senior Journalist
May 3, 2024 1 min read
ADVERTISEMENT
  • The “Downloader” campaign uses fake URL shorteners to redirect users to malware downloads. 9,309 users created 1,453,228 such repositories or 9.7% of all repositories on Docker Hub.
  • The “eBook Phishing” campaign promises free eBooks with randomly generated descriptions but instead steals users' credit card information and enrolls users in costly subscriptions. 1,042 users created 1,069,160 such repositories or 7.1% of all repositories on Docker Hub.
  • The “Website SEO” campaign has no clear goal, as the content of repositories is mostly harmless. Only one repository was created per user. Random phrases without any other information were likely used to boost SEO. 194,699 users created 215,451 repositories (1.4%).
ADVERTISEMENT