"Millions of Malicious 'Imageless' Containers Planted on Docker Hub Over 5 Years"
"Millions of Malicious 'Imageless' Containers Planted on Docker Hub Over 5 Years"
JFrog researchers found multiple campaigns planting millions of malicious "imageless" containers on Docker Hub over the past five years, highlighting how open source registries can enable supply chain attacks. More than four million Docker Hub repositories are imageless and contain only the repository documentation, according to JFrog security researcher Andrey Polkovnichenko. The documentation is unrelated to the container. Instead, it is a page that directs users to phishing or malware sites.