National Cyber Warfare Foundation (NCWF)

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI CD Workflows


0 user ratings
2026-05-22 12:51:10
milo
Attacks
Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window.

"Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that exfiltrate CI



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/05/megalodon-github-attack-targets-5561.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.