supply-chain
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
Critical
Summary
A sophisticated cyberattack, dubbed Megalodon, has targeted over 5,500 GitHub repositories using malicious CI/CD workflows. The attacker leveraged throwaway accounts and forged author identities to exfiltrate sensitive data, including credentials, secrets, and source code, from CI/CD pipelines. This attack highlights a growing trend of supply chain attacks, with TeamPCP identified as the primary actor exploiting open-source tools and leveraging a worm-like propagation strategy.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
