AUTO-UPDATED

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

Cybersecurity researchers have identified the Megalodon campaign, which utilized automated scripts to inject malicious code into over 5,500 GitHub repositories to harvest sensitive cloud and development credentials.

Key Points

  • The Megalodon campaign pushed 5,718 malicious commits to 5,561 GitHub repositories on May 18, 2026.
  • Attackers used forged identities and throwaway accounts to inject base64-encoded bash payloads into GitHub Actions workflows.
  • Stolen data includes AWS, Google Cloud, and Azure credentials, SSH keys, API tokens, and environment variables.
  • Two primary payload variants, SysDiag and Optimize-Build, were deployed to execute malicious code within CI/CD pipelines.
  • The campaign targeted specific projects like @tiledesk/tiledesk-server to gain unauthorized access to build environments.

Why it Matters

This large-scale supply chain attack highlights the increasing vulnerability of automated CI/CD pipelines to credential theft and unauthorized code injection. By compromising widely used repositories, attackers can gain persistent access to sensitive infrastructure, forcing organizations to re-evaluate their reliance on automated tokens and third-party integrations.
Internet Published by info@thehackernews.com (The Hacker News)
Read original