logo

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

ID: 27038a65-a0ef-541c-9bc5-f0e7e4efa5e9

STIX ID: report--27038a65-a0ef-541c-9bc5-f0e7e4efa5e9

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed "Megalodon", an automated supply-chain campaign that pushed 5,718 malicious commits to 5,561 GitHub repositories on May 18, 2026, injecting GitHub Actions workflows with base64-encoded bash payloads that steal CI environment variables, cloud credentials, SSH keys, OIDC/GitHub tokens, and other secrets and exfiltrate them to a C2 at 216.126.225.129:8443; the campaign includes mass (SysDiag) and targeted (Optimize-Build) variants and is tied to broader TeamPCP activity and malicious npm packages that steal crypto private keys via social-engineered postinstall hooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.