logo

Megalodon chums the waters in 5.5K+ GitHub repo poisonings

ID: 3db88d3c-e5f8-5515-944e-87041cd90e16

STIX ID: report--3db88d3c-e5f8-5515-944e-87041cd90e16

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

...
...

A widespread supply-chain campaign called “Megalodon” injected malicious commits into over 5,500 GitHub repositories; if merged, the commits execute inside CI/CD pipelines and deploy credential-stealing malware. The malicious code harvests cloud provider credentials (AWS, GCP, Azure), SSH keys, Docker/Kubernetes configurations, Vault and Terraform secrets, and exfiltrates GitHub/Bitbucket tokens, enabling attacker impersonation and further spread; researchers traced commits to automated-like authors (build-bot, ci-bot) and published a list of compromised repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.