Cybersecurity researchers have identified the Megalodon campaign, which utilized automated scripts to inject malicious code into over 5,500 GitHub repositories to harvest sensitive cloud and development credentials.
Key Points
- The Megalodon campaign pushed 5,718 malicious commits to 5,561 GitHub repositories on May 18, 2026.
- Attackers used forged identities and throwaway accounts to inject base64-encoded bash payloads into GitHub Actions workflows.
- Stolen data includes AWS, Google Cloud, and Azure credentials, SSH keys, API tokens, and environment variables.
- Two primary payload variants, SysDiag and Optimize-Build, were deployed to execute malicious code within CI/CD pipelines.
- The campaign targeted specific projects like @tiledesk/tiledesk-server to gain unauthorized access to build environments.