Megalodon cyberattack infects 5,500 GitHub repositories, report says

TL;DR AI
2 min readKey summary
Researchers say the Megalodon campaign hit 5,561 GitHub repositories with malicious commits on May 18.
The attackers used forged accounts and poisoned GitHub Actions workflow files to trigger payloads across open-source projects.
The malware exfiltrated CI secrets, cloud credentials, SSH keys, OIDC tokens, and source-code secrets to a command server.
The incident highlights how workflow compromise in the software supply chain can spread quickly and expose sensitive access data.

