The Megalodon supply chain attack poisoned over 5,500 GitHub repositories via automated commits injecting GitHub Actions workflows.

Megalodon pushed 5,718 malicious GitHub commits in 6 hours, exposing CI secrets and cloud credentials at scale.

8 Packagist packages hid malicious package.json scripts, enabling Linux binary execution during installs and workflows.

The Megalodon supply chain attack poisoned over 5,500 GitHub repositories via automated commits injecting GitHub Actions workflows.

Megalodon compromette oltre 5.500 repository GitHub rubando token cloud e segreti CI/CD tramite workflow malevoli.

Security researchers say 5,500 GitHub repositories have been affected by the attack.