GitHub hit with another major attack – Megalodon hits over 5,000 repos with malware-laden commits


  • SafeDep researchers uncovered Megalodon, a TeamPCP-inspired campaign that infected over 5,500 GitHub repositories with an infostealer targeting CI/CD secrets
  • The worm-like attack spreads via malicious exploits from a fake “build-bot” that steals cloud keys, SSH credentials and DevOps configurations, with npm packages like Tiledesk inadvertently published from poisoned repositories
  • Unlike TeamPCP’s forum “competition”, Megalodon appears to be a separate copycat actor motivated by recent supply chain attacks, posing risks to both maintainers and downstream users

It looks like we’ve got our first TeamPCP copycat, and it’s called Megalodon.

Late last week, security researchers reported to SafeDep that they found more than 5,500 GitHub repositories infected with an infostealer that captures all sorts of secrets from victim developers’ CI/CD pipeline.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top