logo

5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours

ID: 5e462308-0e78-5e49-b1af-a1794338d21d

STIX ID: report--5e462308-0e78-5e49-b1af-a1794338d21d

Feed Name: HackRead

Threat Score
85/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Deeba Ahmed

...
...

A campaign dubbed “Megalodon” automated thousands of fake code updates across ~5,561 GitHub repositories in a short window, adding malicious GitHub Actions workflows and replacing system files to install a dormant backdoor. The backdoor decodes and runs a background program that harvests cloud credentials (AWS, GCP, Azure), system logs, and secret tokens, exfiltrating data to C2 at 216.126.225.129:8443; infected npm packages from Tiledesk were published publicly, demonstrating active exploitation and supply-chain impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.