logo

Megalodon Supply Chain Attack Hits 5,500+ GitHub Repositories in Six Hours

ID: 2012153d-4a04-50af-a647-411ae02a8e95

STIX ID: report--2012153d-4a04-50af-a647-411ae02a8e95

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Ashish Khaitan

...
...

**Megalodon supply-chain campaign** — On May 18, 2026 attackers pushed 5,718 malicious commits across 5,561 GitHub repositories within ~6 hours, adding or replacing GitHub Actions workflows that harvested CI/CD and cloud credentials (AWS, GCP, Azure), tokens, SSH keys and other secrets; the campaign used workflow_dispatch to create dormant backdoors and led to compromised NPM package releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.