CybersecurityVerified Users Only
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
The Hacker NewsยทMay 22, 2026ยท1 min read
Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window. "Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that exfiltrate CI
Read full article on The Hacker News โShare this article
Follow broker incidents, regulatory actions & market intelligence
Stay ahead with CLEAREX.MARKET
View all intelligence โ