GitHub falls victim to another major attack: Megalodon hits over 5,000 repositories with malware-laden commits


  • SafeDep researchers discovered Megalodon, a TeamPCP-inspired campaign infecting over 5,500 GitHub repositories with an information stealer targeting CI/CD secrets.
  • The worm attack spreads via malicious commits from a fake “build bot”, stealing cloud keys, SSH credentials and DevOps configurations, with npm packages like Tiledesk inadvertently released from poisoned repositories.
  • Unlike TeamPCP’s “competition” forum, Megalodon appears to be a separate copycat actor motivated by recent supply chain attacks, posing risks to both maintainers and downstream users.

It looks like we’ve gotten our first TeamPCP copycat, and it’s called Megalodon.

Late last week, security researchers SafeDep reported discovering more than 5,500 GitHub repositories infected with an information stealer that scrapes all kinds of secrets from victim developers’ CI/CD pipeline.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top