{"id":1015,"date":"2026-05-22T13:29:33","date_gmt":"2026-05-22T13:29:33","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1015"},"modified":"2026-05-22T13:29:33","modified_gmt":"2026-05-22T13:29:33","slug":"megalodon-github-attack-targets-5561-repos-with-malicious-ci-cd-workflows","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1015","title":{"rendered":"Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI\/CD Workflows"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjC_sjVeLejyyBZJ0DWW2y9-Z2Jvmrzz9h-5XEIKPFTcJvDj49Jlt-z1FNbSp51K9XcQ8FqC9MBDFPPPdZuzRfjqtYvKNaqT0Qzd61oCHVhNq59IcAVcWV3LvDmKCsX5pHn4nU3LclQPEozMp3XsgYZnVHCZEj89AGkWJpqL1EjCjiqMLnvggZLsgb08MYp\/s1700-e365\/github-worm.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of a new automated campaign called <b>Megalodon<\/b> that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window.<\/p>\n<p>\u00abUsing throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that exfiltrate CI secrets, cloud credentials, SSH keys, OIDC tokens, and source code secrets to a C2 server at 216.126.225[.]129:8443,\u00bb SafeDep <a href=\"https:\/\/safedep.io\/megalodon-mass-github-repo-backdooring-ci-workflows\/\" target=\"_blank\">said<\/a> in a report.<\/p>\n<p>The complete list of data harvested by the malware is below &#8211;<\/p>\n<ul>\n<li>CI environment variables, \/proc\/*\/environ, and PID 1 environment<\/li>\n<li>Amazon Web Services (AWS) credentials<\/li>\n<li>Google Cloud access tokens<\/li>\n<li>Instance role credentials obtained by querying AWS IMDSv2, Google Cloud metadata, and Microsoft Azure Instance Metadata Service (IMDS) endpoints<\/li>\n<li>SSH private keys<\/li>\n<li>Docker and Kubernetes configurations<\/li>\n<li>Vault tokens<\/li>\n<li>Terraform credentials<\/li>\n<li>Shell history<\/li>\n<li>API keys, database connection strings, JWTs, PEM private keys, and cloud tokens matching more than 30 secret regular expression patterns<\/li>\n<li>GitHub Actions OIDC token request URL and token<\/li>\n<li>GITHUB_TOKEN, GitLab CI\/CD tokens, and Bitbucket tokens<\/li>\n<li>.env files, credentials.json, service-account.json, and other configuration files<\/li>\n<\/ul>\n<p>One of the impacted packages is @tiledesk\/tiledesk-server, which bundles a Base64-encoded bash payload within a GitHub Actions workflow file. In all, 5,718 commits were pushed against 5,561 distinct repositories on May 18, 2026, between 11:36 a.m. and 5:48 p.m. UTC.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThe attacker rotated through four author names (build-bot, auto-ci, ci-bot, pipeline-bot) and seven commit messages, all mimicking routine CI maintenance,\u00bb SafeDep said. \u00abThe attacker used throwaway GitHub accounts with random 8-character usernames (e.g., rkb8el9r, bhlru9nr, lo6wt4t6), set git config to forge the author identity, and pushed via compromised PATs or deploy keys.\u00bb<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Two payload variants have been observed as part of the large-scale campaign: SysDiag, a mass variant which adds a new workflow that&#8217;s triggered on every push and pull request, and Optimize-Build, a targeted variant that activates only on <a href=\"https:\/\/docs.github.com\/en\/actions\/reference\/workflows-and-actions\/events-that-trigger-workflows#workflow_dispatch\" target=\"_blank\">workflow_dispatch<\/a>, a GitHub Actions trigger that allows users to manually run a workflow on-demand. In the case of Tiledesk, the targeted approach is used to target CI\/CD runners, and not when the npm package is installed.<\/p>\n<p>\u00abThe tradeoff is reach: on: push would guarantee execution on every commit to master, hitting more targets without intervention,\u00bb SafeDep added. \u00abWorkflow_dispatch sacrifices that for operational security. With 5,700+ repos compromised, even a small fraction yielding a usable GITHUB_TOKEN gives the attacker enough targets for on-demand triggering.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjgOi30e1RABlSxe7QyIGD14Z6CB-6zwYwf4Y3Xsecd5do01dlAZwYRJW2X16QpT90e3N9pKh8zh9THZtJJ-5KBK39DBDWSjJ0iXfxxclJ4Uz8N4wLFIPKts7jWdyD1XSm4czO7-cpOmP7s0MgdZG-4HRXFsDGhMsojb0Opxo2R8eKWeWTHXTJfPNV5YGe1\/s1700-e365\/megalodon.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjgOi30e1RABlSxe7QyIGD14Z6CB-6zwYwf4Y3Xsecd5do01dlAZwYRJW2X16QpT90e3N9pKh8zh9THZtJJ-5KBK39DBDWSjJ0iXfxxclJ4Uz8N4wLFIPKts7jWdyD1XSm4czO7-cpOmP7s0MgdZG-4HRXFsDGhMsojb0Opxo2R8eKWeWTHXTJfPNV5YGe1\/s1700-e365\/megalodon.jpg\" alt=\"\" border=\"0\" data-original-height=\"787\" data-original-width=\"1024\"\/><\/a><\/div>\n<p>The result is that once a repository owner merges the commit, the malware executes inside their CI\/CD pipelines and spreads further, enabling the theft of credentials and secrets at scale.<\/p>\n<p>\u00abWe&#8217;ve entered a new supply chain attack era, and TeamPCP compromising GitHub was only the beginning,\u00bb OX Security&#8217;s Moshe Siman Tov Bustan <a href=\"https:\/\/www.ox.security\/blog\/megalodon-cicd-malware-github\/\" target=\"_blank\">said<\/a>. \u00abWhat&#8217;s coming next is an endless wave, a tsunami of cyber attacks on developers worldwide.\u00bb<\/p>\n<p>The development comes as TeamPCP has weaponized the interlinked software supply chain to corrupt hundreds of open-source tools, worming their way through several ecosystems and extorting victims for profit in some cases. Microsoft-owned GitHub has become the latest addition to the group&#8217;s long list of victims, which also includes TanStack, Grafana Labs, OpenAI, and Mistral AI.<\/p>\n<p>TeamPCP attacks have fueled a cyclical exploitation of popular open-source projects, where one compromise feeds the next, allowing the malware to spread like wildfire in a worm-like fashion. The group also appears to be financially motivated and has established partnerships with BreachForums and other extortion crews like LAPSUS$ and VECT.<\/p>\n<p>What&#8217;s more, the group seems to be geopolitically motivated as well, as evidenced by the deployment of wiper malware upon detecting machines located in Iran and Israel.<\/p>\n<p>The fallout from TeamPCP&#8217;s attack spree and the <a href=\"https:\/\/trustedsec.com\/blog\/shai-hulud-is-back\" target=\"_blank\">Mini Shai-Hulud worm<\/a> has <a href=\"https:\/\/x.com\/npmjs\/status\/2056960835030016286\" target=\"_blank\">prompted<\/a> npm to invalidate granular access tokens with write access that bypasses two-factor authentication (2FA). NPM is also urging users to switch to <a href=\"https:\/\/docs.npmjs.com\/trusted-publishers\/\" target=\"_blank\">Trusted Publishing<\/a> to reduce reliance on such tokens.<\/p>\n<p>\u00abBy burning every bypass-2FA token on the platform, npm cuts off the credentials the worm has already collected,\u00bb application security firm Socket <a href=\"https:\/\/socket.dev\/blog\/npm-invalidates-tokens-mini-shai-hulud\" target=\"_blank\">said<\/a>. \u00abMaintainers issue new ones. The worm, still active in the wild, goes back to harvesting them. The reset buys breathing room. It does not close the underlying hole.\u00bb<\/p>\n<p>Activity clusters like Megalodon and TeamPCP involve compromising legitimate packages to distribute malware. In contrast, a throwaway account named \u00ab<a href=\"https:\/\/www.npmjs.com\/~polymarketdev\" target=\"_blank\">polymarketdev<\/a>\u00bb has been found to publish nine malicious npm packages impersonating Polymarket trading CLI tools within a 30-second window to steal victims&#8217; Ethereum\/Polygon private keys via a postinstall hook.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>As of writing, they are still available for download from npm. The names of the packages are below &#8211;<\/p>\n<ul>\n<li>polymarket-trading-cli<\/li>\n<li>polymarket-terminal<\/li>\n<li>polymarket-trade<\/li>\n<li>polymarket-auto-trade<\/li>\n<li>polymarket-copy-trading<\/li>\n<li>polymarket-bot<\/li>\n<li>polymarket-claude-code<\/li>\n<li>polymarket-ai-agent<\/li>\n<li>polymarket-trader<\/li>\n<\/ul>\n<p>\u00abOn install, a postinstall script displays a fake wallet onboarding prompt that asks the user to paste their private key, claiming &#8216;it stays encrypted,'\u00bb SafeDep <a href=\"https:\/\/safedep.io\/malicious-polymarket-npm-crypto-wallet-drainer\/\" target=\"_blank\">said<\/a>. \u00abThe script POSTs the raw key in plaintext to a Cloudflare Worker at hxxps:\/\/polymarketbot.polymarketdev.workers[.]dev\/v1\/wallets\/keys.\u00bb<\/p>\n<p>\u00abThe attacker built a functional trading CLI around a credential theft operation. Social engineering carries the attack: the postinstall prompt looks like standard wallet onboarding, the masking mimics secure input, and the GitHub repo provides false credibility\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window. \u00abUsing throwaway accounts and&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1016,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[220,576,71,33,1767,153,78,555],"class_list":["post-1015","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attack","tag-cicd","tag-github","tag-malicious","tag-megalodon","tag-repos","tag-targets","tag-workflows"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1015","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1015"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1015\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1016"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1015"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1015"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1015"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}