GitHub suffered another major attack: Megalodon hits more than 5,000 repositories with malware-laden commits



  • SafeDep researchers discovered Megalodon, a TeamPCP-inspired campaign that infects more than 5,500 GitHub repositories with an information stealer targeting CI/CD secrets.
  • The worm-like attack spreads via malicious commits from a fake “build bot”, which steals cloud keys, SSH credentials and DevOps configurations, with npm packages like Tiledesk inadvertently published from poisoned repositories.
  • Unlike the “competition” on the TeamPCP forum, Megalodon appears to be an independent copycat actor motivated by recent supply chain attacks, posing risks to both maintainers and downstream users.

It looks like we have our first TeamPCP copycat and it’s called Megalodon.

Late last week, SafeDep security researchers reported finding more than 5,500 GitHub repositories infected with a data stealer that captures all sorts of CI/CD process secrets from victim developers.

Leave a Comment

Your email address will not be published. Required fields are marked *