logo

Megalodon Malware Compromised 5,500+ GitHub Repositories.

ID: 11bd3c3a-bb68-5734-998f-18b97a7f56c3

STIX ID: report--11bd3c3a-bb68-5734-998f-18b97a7f56c3

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Lucas Martin

...
...

Megalodon is a large, automated GitHub supply-chain campaign that between 11:36 and 17:48 UTC on May 18, 2026 pushed 5,718 malicious commits across 5,561 repositories using throwaway accounts and forged bot identities to install workflow backdoors that exfiltrate CI secrets, cloud credentials, and source code; it included a mass 'SysDiag' workflow and a stealthy 'Optimize-Build' workflow_dispatch variant, and poisoned the npm package @tiledesk/tiledesk-server (v2.18.6–2.18.12), with a C2 at 216.126.225.129:8443 and detailed IoCs and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.