Who's Pushing the Code? An Exploration of GitHub Impersonation
Yueke Zhang, Anda Liang, Xiaohan Wang, Pamela J. Wisniewski, Fengwei Zhang, Kevin Leach, Yu Huang
Abstract
GitHub is one of the largest open-source software (OSS) communities for software development and collaboration. Impersonation in the OSS communities refers to the malicious act of assuming another user's identity, often aiming to gain unauthorized access to code, manipulate project outcomes, or spread misinformation. With several recent real-world attacks resulting from impersonation, this issue is becoming more and more concerning within the OSS community. We present the first exploration of the impact of impersonation in GitHub. Specifically, we conduct structured interviews with 17 real-world OSS contributors about their perception of impersonation and corresponding mitigations. Our study reveals that, in general, GitHub users lack awareness of impersonation and underestimate the severity of its implications. After witnessing a demo of impersonation, they show significant concern for the OSS community. Meanwhile, we also demonstrate that the current best practices (i.e., commit signing) that might mitigate impersonation must be improved to encourage use and adoption. We also present and discuss participant perceptions of potential ways to mitigate GitHub impersonation. We collect a dataset comprising 12.5 million commits to investigate the current status of impersonation. Interestingly, we find out that currently impersonation cannot be easily detected. We observe that existing commit histories treat impersonation behavior identically to pull request events, resulting in a lack of detection methods for impersonation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6bd98753-6e1c-48b5-b992-ee9b4b7d9ae0Cited by top-tier papers1
Ask how each one uses itBuilds on6
- Leaving My Fingerprints: Motivations and Challenges of Contributing to OSS for Social GoodYu Huang, Denae Ford, Thomas ZimmermannICSE 2021 · 36 citations
- Automated Detection of Password Leakage from Public GitHub RepositoriesRunhan Feng, Ziyang Yan, Shiyan Peng, Yuanyuan ZhangICSE 2022 · 36 citations
- On Omitting Commits and Committing Omissions: Preventing Git Metadata Tampering That (Re)introduces Software VulnerabilitiesSantiago Torres-Arias, Anil Kumar Ammula, Reza Curtmola, Justin CapposUSENIX Security 2016 · 33 citations
- Hashing It Out: A Survey of Programmers' Cannabis Usage, Perception, and MotivationMadeline Endres, Kevin Boehnke, Westley WeimerICSE 2022 · 11 citations
- SoK: Taxonomy of Attacks on Open-Source Software Supply ChainsPiergiorgio Ladisa, Henrik Plate, Matias Martinez, Olivier BaraisS&P 2023
Related papers
- Attributing Open-Source Contributions is Critical but Difficult: A Systematic Analysis of GitHub Practices and Their Impact on Software Supply Chain SecurityJan-Ulrich Holtgrave, Kay Friedrich, Fabian Fischer, Nicolas Huaman et al.NDSS 2025
- Mining Pull Requests to Detect Process Anomalies in Open Source Software DevelopmentBohan Liu, He Zhang, Weigang Ma, Hongyu Kuang et al.ICSE 2024 · 2 citations
- The Landscape of Toxicity: An Empirical Investigation of Toxicity on GitHubJaydeb Sarker, Asif Kamal Turzo, Amiangshu BosuFSE 2025 · 1 citation
- How Bad Can It Git? Characterizing Secret Leakage in Public GitHub RepositoriesMichael Meli, Matthew R. McNiece, Bradley ReavesNDSS 2019 · 130 citations
- A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security FeaturesJessy Ayala, Yu-Jye Tung, Joshua GarciaUSENIX Security 2025
