techjacksolutions.com • 3h
Megalodon Campaign: Mass CI/CD Poisoning of GitHub Repositories
The Megalodon campaign is a highly automated supply chain attack that compromised over 5,500 GitHub repositories within a six-hour window by poisoning CI/CD pipelines. Threat actors modified .github/workflows/*.yml configuration files to inject malicious scripts designed to exfiltrate developer credentials, cloud provider tokens, and sensitive environment variables. The attack leverages the trusted execution environment of GitHub Actions to capture secrets during the build process and transmit them to external Command and Control (C2) infrastructure. This represents a tactical shift from targeted repository exploitation to mass-scale, automated harvesting of secrets across the software development lifecycle (SDLC).
Links:techjacksolutions.com, Darkreading, Labs, Kaseya, Ox, Reddit, Socfortress, Infostealers, Youtube, Safedep •