New Attack "Megaladon" Compromises 5.5K+ GitHub Repos (theregister.com)
0xBASE INTEL BRIEF
- Over 5,500 GitHub repos were compromised in a coordinated attack named 'Megaladon'.
- Attackers used stolen tokens to inject malicious code and exfiltrate credentials.
- The attack likely targeted supply chain security, affecting multiple downstream projects.
"A newly discovered campaign named "Megaladon" has compromised over 5,500 GitHub repositories, likely through credential theft or CI/CD pipeline attacks. The attackers injected malicious code to exfiltrate secrets and potentially establish supply chain infections. This event underscores ongoing risks in open-source software ecosystems and the need for robust token management and auditing."
no comments yet.