A malicious installation link was discovered embedded in the GitHub Wiki documentation for Mockito, a widely used Java mocking framework. The link, which pointed to a third-party URL (https://yip[.]su/2F5rd4), was flagged as malicious by VirusTotal and was unrelated to the official Mockito project. The compromised link was present in the Wiki’s installation section for over three years before its removal, raising concerns about the potential exposure of users to malware during that period. The injected HTML rendered download buttons, specifically including a Windows installer link that redirected to the malicious URL, while the Mac and Linux links pointed to legitimate Mockito release pages. The malicious link was inserted in a way that made it appear as an official download option, increasing the likelihood that unsuspecting users would click it. Evidence of the compromise is visible in the Wiki’s revision history, which shows the addition and subsequent removal of the malicious content. The issue was discussed in the project's GitHub issue tracker, where maintainers and users highlighted the risks and the need for better controls over documentation edits. The malicious link was not only present in the HTML but also disguised as a download button, further obfuscating its true nature. VirusTotal analysis confirmed the link’s malicious status, indicating it could have been used to distribute malware or conduct phishing attacks. The incident underscores the risks associated with open documentation platforms like GitHub Wikis, where insufficient access controls can allow attackers to inject harmful content. Security experts recommend that project maintainers lock down their Wikis and restrict editing permissions to trusted contributors. The long duration of the compromise suggests that many users may have been exposed, though the exact number of affected downloads is unknown. The incident has prompted calls for more rigorous monitoring and auditing of open source project documentation. This case highlights the importance of verifying download links and the potential for supply chain attacks via documentation tampering. Project maintainers are urged to regularly review and audit their documentation for unauthorized changes. The broader open source community is advised to treat documentation as a potential attack vector and implement appropriate security measures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
The Mockito documentation site was reportedly hijacked, forming the core security incident described by the references. No additional dated milestones, remediation actions, or impact details are provided in the supplied content.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.