logo

Researcher's Notebook: Hunting Megalodon Fossils

ID: 7f9ac27a-12fb-5304-adbb-8c586bc2286e

STIX ID: report--7f9ac27a-12fb-5304-adbb-8c586bc2286e

Feed Name: ReversingLabs Blog

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-05-27

Author: Robert Simmons

...
...

The report documents the "megalodon" supply-chain campaign that compromised many GitHub Action CI configurations by adding a base64-encoded malicious script which contacts a NEXUS Listener C2 (examples: 216.126.225.129 and several 144.172.x.x addresses). Analysis links this activity to earlier credential-stealing and coin-mining campaigns, provides IOCs (C2 URLs and IPs), a YARA rule for detection, and retrohunt results demonstrating historical telemetry and campaign linkage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.