Cybersecurity · 31 views
GitHub Actions abused by Megalodon attack to slip malicious commits into 5,500 repos
A large-scale automated GitHub backdooring campaign was caught pushing thousands of malicious commits into public repositories while posing as routine CI/CD upkeep.
AI Summary
Researchers at SafeDep detected a large‑scale automated GitHub backdooring campaign, Megalodon, that pushed malicious commits into more than 5,500 public repositories in a six‑hour window on May 18. The campaign inserted a commit (acac5a9) that modified GitHub Actions workflows to include base64‑encoded bash payloads designed to steal secrets exposed during CI execution, such as cloud credentials, SSH keys, OIDC tokens, and other environment variables. The attackers used the workflow_dispatch trigger, which can appear as routine CI/CD upkeep, and the researchers warned that unexpected workflow_dispatch runs could signal a compromise. Notable victims included Wiznet’s ioLibrary_Driver, four Tiledesk repositories, and four persian‑tools repositories, which together received over 2,000 malicious commits.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedMore from Cybersecurity
Continue reading recent Cybersecurity coverage
- Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin TheftContinue reading
- Webinar: The forgotten Google Workspace access that can lead to a breachContinue reading
- Hackers build AI frameworks for widescale credential theftContinue reading
- WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming CallsContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow