Summary

A massive supply chain attack dubbed “Megalodon” has infected over 5,500 GitHub repositories with credential-stealing malware. The attack, discovered by security firm SafeDep, relied on automated commits that injected malicious GitHub Actions workflows into 5,561 distinct repositories within a six-hour window on May 18, 2026.

The attackers deployed two payloads: one that added a new workflow triggered on every push and pull request, and another that replaced existing workflows with dormant backdoors. Once activated, the malware exfiltrates CI environment variables, AWS/GCP/Azure credentials, SSH private keys, Docker and Kubernetes configurations, API keys, database connection strings, and dozens of other types of secrets.

The attack was traced back to compromised versions of the Tiledesk package, an open-source live chat platform. The attacker compromised the GitHub repository itself, and the maintainer unknowingly published from the poisoned source. A total of 5,718 malicious commits were pushed via two email addresses associated with a “build-bot” author account.

Source

📰 SecurityWeek — Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack

📰 SafeDep — Full Technical Analysis

Commentary

Coming just weeks after the TeamPCP breach that saw 3,800 internal GitHub repositories exfiltrated, Megalodon represents a dangerous escalation in supply chain attacks. The attackers’ use of workflow_dispatch — which bypasses GitHub’s anti-recursion protections — shows a sophisticated understanding of CI/CD infrastructure that most defenders haven’t caught up with.

The fact that NPM has now invalidated all granular write-access tokens that bypass 2FA is a step in the right direction, but as Ox Security notes, it doesn’t solve the underlying problem. We’re entering a phase where the development pipeline itself is the attack surface, and most organizations still treat CI/CD as a trusted internal system. That assumption is now definitively broken.

By Allan