Researchers disclosed a large-scale automated supply chain attack dubbed Megalodon that pushed 5,718 malicious commits into 5,561 GitHub repositories in less than six hours, using forged CI/CD bot identities and benign-looking commit messages to slip in malicious GitHub Actions workflow files. The workflows requested elevated permissions and carried base64-encoded bash payloads that executed after maintainers merged the changes, harvesting CI/CD environment data, cloud credentials, SSH keys, Docker and Kubernetes secrets, Vault and Terraform credentials, GitHub OIDC tokens, and other source-code and developer secrets. Investigators said the stolen data was exfiltrated over HTTP POST requests to 216.126.225[.]129:8443, with two workflow variants observed, including payloads labeled SysDiag and Optimize-Build.
The most visible downstream impact was a compromise of the Tiledesk repository, where a malicious workflow change led to the publication of poisoned @tiledesk/tiledesk-server npm versions 2.18.6 through 2.18.12. Reporting tied the activity to a broader pattern of software supply chain abuse associated with TeamPCP, whose earlier incidents affected major open-source and commercial projects and prompted npm to invalidate some write-capable granular access tokens that could bypass 2FA protections. Security firms urged organizations to review repositories for unauthorized workflow changes, block the identified command-and-control infrastructure, rotate exposed secrets and keys, and inspect cloud and CI logs for signs of credential theft or cloud impersonation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
More than a week after the May 18 Megalodon campaign, OX Security said it had initially identified about 3,500 affected GitHub repositories and later estimated roughly 2,900 still remained infected. The assessment indicated the malicious workflow implants persisted well beyond the initial six-hour mass compromise window.
StepSecurity reported that Black-Iron-Project and WISE-Community were among the confirmed repositories compromised in the Megalodon campaign, expanding the list of specifically named victims beyond Tiledesk. The report placed these victim disclosures in the context of the May 18 mass GitHub Actions workflow compromise affecting 5,561 repositories.
SafeDep separately identified a throwaway npm publisher, polymarketdev, that uploaded nine malicious Polymarket-themed packages intended to trick users into submitting Ethereum or Polygon private keys to a Cloudflare Worker endpoint. The packages were reported in coverage of the broader Megalodon and related supply chain activity.
By 2026-05-21, SafeDep had publicly reported the Megalodon campaign, stating that thousands of repositories were affected and detailing the malicious workflow techniques and credential theft behavior. Reporting also connected the activity to a broader software supply chain abuse wave associated with TeamPCP.
As a downstream impact of the GitHub compromises, a malicious workflow change in the Tiledesk repository resulted in the maintainer publishing compromised @tiledesk/tiledesk-server npm versions 2.18.6 through 2.18.12. SafeDep identified the embedded payload in the Tiledesk package and linked it to the broader Megalodon campaign.
The implanted GitHub Actions workflows deployed base64-encoded bash payloads that harvested CI environment data, cloud credentials, SSH keys, Docker and Kubernetes secrets, Vault and Terraform credentials, GitHub OIDC tokens, and other source-code-related secrets. Researchers said the stolen data was exfiltrated to 216.126.225.129:8443, including via HTTP POST requests using the parameter string "megalodon."
On 2026-05-18, an automated supply chain attack dubbed Megalodon pushed 5,718 malicious commits into 5,561 GitHub repositories within roughly six hours. The commits used fake CI/CD bot-style identities and inserted malicious GitHub Actions workflow files designed to run after merges or remain dormant for later activation.
A separate supply chain incident reportedly involved a Claude-powered AI bot compromising five major GitHub repositories. This predates the May 2026 Megalodon campaign and represents a distinct repository compromise event.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
protoslabs.io
Open sourcecommunity.gurucul.com
Open sourcecysecurity.news
Open sourcesafedep.io
Open sourcetheregister.com
Open sourcethreats.wiz.io
Open sourceox.security
Open sourcecybernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.