AquaSec analysed a sample of 1.25 million GitHub repositories and found that about 37,000 of them are vulnerable to RepoJacking, including companies such as Google and Lyft.
While currently used to push adware, the campaign can redirect users to other types of malware, such as banking trojans to steal credentials and financial information or ransomware.