news.mlab.sh
Back to the feed
supply-chain

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

Critical
Image: The Hacker News
Summary

A sophisticated cyberattack, dubbed Megalodon, has targeted over 5,500 GitHub repositories using malicious CI/CD workflows. The attacker leveraged throwaway accounts and forged author identities to exfiltrate sensitive data, including credentials, secrets, and source code, from CI/CD pipelines. This attack highlights a growing trend of supply chain attacks, with TeamPCP identified as the primary actor exploiting open-source tools and leveraging a worm-like propagation strategy.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.