Researcher's Notebook: Hunting Megalodon Fossils
ID: 7f9ac27a-12fb-5304-adbb-8c586bc2286e
STIX ID: report--7f9ac27a-12fb-5304-adbb-8c586bc2286e
Feed Name: ReversingLabs Blog
Threat Score
The report documents the "megalodon" supply-chain campaign that compromised many GitHub Action CI configurations by adding a base64-encoded malicious script which contacts a NEXUS Listener C2 (examples: 216.126.225.129 and several 144.172.x.x addresses). Analysis links this activity to earlier credential-stealing and coin-mining campaigns, provides IOCs (C2 URLs and IPs), a YARA rule for detection, and retrohunt results demonstrating historical telemetry and campaign linkage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
