Megalodon is an automated software supply-chain intrusion campaign focused on compromising GitHub repositories at scale in order to steal CI/CD secrets, cloud credentials, source-code secrets, and developer infrastructure access. The campaign is notable for pushing thousands of malicious commits into public repositories within a short time window, using forged CI-style bot identities and routine-looking commit messages to blend into normal development activity. Researchers observed the operation affecting more than 5,500 repositories and using malicious GitHub Actions workflow injections so that, if a maintainer merged the poisoned commit, the payload would execute inside the victim repository’s CI/CD environment. Megalodon’s tradecraft centers on credential theft and post-compromise propagation through developer and build environments. Observed payloads harvested CI environment variables, cloud access material, GitHub and Bitbucket tokens, SSH keys, container and Kubernetes configuration, Vault and Terraform credentials, shell history, and other secrets exposed to runners or present in repositories. The malware also queried cloud metadata services to obtain instance-role credentials and searched source code and configuration files for numerous secret patterns. Two payload variants, referred to as SysDiag and Optimize-Build, were reported; one variant established broad workflow-based execution on repository activity, while another was tailored to execute in CI/CD runners after a malicious commit was merged. The campaign also included targeted repository backdooring that led maintainers to publish poisoned software from compromised source code. In one documented case, a legitimate package was backdoored through its GitHub repository rather than through direct compromise of the package registry account, causing the maintainer to unknowingly release malicious versions. This reflects a broader emphasis on subverting trusted development and release workflows rather than only stealing package-publishing credentials. Megalodon has been assessed as resembling earlier TeamPCP and Mini Shai-Hulud-style supply-chain operations in tactics and style, particularly around ecosystem-scale automation and secret harvesting, but available reporting did not establish a direct attribution to TeamPCP. Some researchers assessed it was likely a different actor imitating that tradecraft. High-confidence reporting supports describing Megalodon as a large-scale supply-chain threat actor or campaign specializing in GitHub-centric initial access, CI/CD secret theft, cloud credential harvesting, and follow-on compromise of developer infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named Shai-Hulud-related campaign that poisoned repositories and CI/CD workflows at scale using mass malicious commits and package compromise.
A separate campaign focused on injecting malicious GitHub Actions workflows into public repositories to steal CI/CD secrets and cloud credentials.
Automated software supply chain campaign compromising GitHub repositories by pushing malicious commits that add GitHub Actions workflows to exfiltrate CI/CD secrets, cloud credentials, SSH keys, OIDC tokens, and source code secrets at scale.
Automated software supply-chain campaign that pushed malicious commits to thousands of GitHub repositories to steal CI/CD and cloud credentials and propagate through poisoned source code.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.