The reconnaissance, while not inherently malicious, poses significant risks: when successful, it can expose internal codebases, developer workflows, and even sensitive credentials, leaving organizations vulnerable to further exploitation.
GreyNoise, which tracks scanning activity through its Git Config Crawler tag, recorded nearly 4,800 unique IP addresses daily during the April spike-substantially higher than the usual baseline.
The majority of these IPs have been classified as malicious, with 95% of all observed IPs in the past 90 days exhibiting hostile intent.
Notably, Singapore emerged as both the top source and destination for this traffic, followed by the United States and Germany.
The IPs involved are associated with major cloud infrastructure providers, including Cloudflare, Amazon, and DigitalOcean.
The recent spike is the fourth significant surge since September 2024, but by far the largest.
Previous spikes involved around 3,000 unique IPs each, underscoring an escalating trend in attempts to locate and exploit exposed Git configuration files.
| Country | Unique Source IPs | Unique Destination IPs |
|---|---|---|
| Singapore | 4,933 | 8,265 |
| United States | 3,807 | 5,143 |
| Germany | 473 | 4,138 |
| United Kingdom | 395 | 3,417 |
| Netherlands | 321 | – |
| India | – | 3,373 |
Exposed Git configuration files can provide attackers with:
If the entire .git directory is accessible, attackers may reconstruct the full codebase, including commit histories that could contain confidential information, credentials, or sensitive business logic.
In 2024, a similar breach led to the exposure of 15,000 credentials and the cloning of 10,000 private repositories.
To mitigate these risks, organizations should:
.git/ Directories are not accessible via public web servers.git/config and similar pathsGreyNoise continues to monitor this evolving threat landscape.
For ongoing updates, readers are encouraged to subscribe to their blog.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates
The post Spike in Git Config Crawling: 4,800+ IPs Targeting Exposed Repositories appeared first on Cyber Security News.
Emily Wood considers herself news savvy. She stays on top of current events and is…
Target’s massive Pokémon collaboration is now available online. The collection, announced back in April, celebrates…
NORTHAMPTON — Light rain and cool temperatures didn’t dampen the spirits at Hampshire Pride, which…
SOUTHAMPTON — Residents took the first step to passing either a $2.5 or $1.9 million Proposition…
SUNDERLAND — In a 430-188 vote, Sunderland voters gave the final approval needed for an…
WILLIAMSBURG — Voters will decide one contested race in Monday’s town election ballot as incumbent…
This website uses cookies.