Megalodon is a large-scale GitHub supply-chain malware campaign centered on malicious modifications to GitHub Actions workflows in public repositories. Active in May 2026, it used forged bot-like commit identities and automated mass commit activity to poison thousands of repositories within a short time window. The campaign abused trusted CI/CD automation by inserting or replacing workflow definitions so that, if maintainers accepted the changes, attacker-controlled code would execute inside GitHub Actions environments.
Its primary objective was credential and secret theft from CI/CD pipelines and adjacent developer or cloud environments. Reported collection targets included GitHub tokens, GitHub Actions OpenID Connect tokens, cloud credentials from AWS, Google Cloud, and Azure, SSH keys, API keys, database secrets, container and Kubernetes configuration, Vault and Terraform credentials, npm and other developer secrets, and source-code-resident secrets identified through pattern matching. The payloads were obfuscated, including base64-encoded shell logic, and some variants queried cloud metadata services to obtain live instance or workload credentials. Investigators also reported external command-and-control communication for exfiltration and tasking.
Two workflow patterns were prominently associated with Megalodon. One broadly triggered on repository activity such as pushes or pull requests to maximize execution opportunities. Another replaced existing workflows with a dormant workflow-dispatch backdoor that could remain largely invisible until remotely activated through the GitHub API. This gave the operators both mass credential harvesting capability and a stealthier persistence mechanism inside repository automation.
Megalodon was notable for downstream software supply-chain impact. In at least one documented case, a compromised repository’s poisoned workflow led maintainers to publish malicious package releases from otherwise legitimate source code, extending exposure to downstream users and CI systems. The campaign therefore functioned as both a repository backdooring operation and a credential-stealing CI/CD implant that could facilitate further compromise.
Public reporting has noted superficial tradecraft similarities to TeamPCP-era supply-chain activity, including fake automation identities and timing overlap with other ecosystem attacks, but direct attribution remains unconfirmed. High-confidence reporting supports describing Megalodon as a CI/CD-focused credential-harvesting malware campaign targeting GitHub-hosted development workflows and the broader open-source software supply chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-48027 was assigned to the malicious extension and added to CISA’s Known Exploited Vulnerabilities catalog. CISA said organizations should treat any machine that ran the compromised extension as fully compromised.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
cybersecurity startup SafeDep flagged an automated malware campaign, codenamed "Megalodon," that unfolded on May 18 in a six-hour window. In that brief amount of time, Megalodon managed to push 5,718 malicious commits to 5,561 GitHub repositories.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
JFrog identified the activity while investigating suspicious behavior linked to a developer account within the Arweave/WeaveDB open source ecosystem.
This diary continues the Internet Storm Center's tracking of the TeamPCP supply chain campaign... the same techniques, subverted build pipelines that emit validly signed artifacts and install-time credential theft
JFrog identified the activity while investigating suspicious behavior linked to a developer account within the Arweave/WeaveDB open source ecosystem.
The primary malware adds a malicious YAML file named "SysDiag" that adds a new workflow whenever a push or pull request is made. The more targeted, secondary payload replaces existing workflows with a "workflow-dispatch" trigger that acts as stealth backdoor.
One payload introduced a new GitHub Actions workflow configured to run on every push and pull request... the malicious workflow leveraged this trigger mechanism to establish dormant backdoors that could later be activated through the GitHub API using stolen GitHub tokens.
JFrog identified the activity while investigating suspicious behavior linked to a developer account within the Arweave/WeaveDB open source ecosystem.
One payload introduced a new GitHub Actions workflow configured to run on every push and pull request... the malicious workflow leveraged this trigger mechanism to establish dormant backdoors that could later be activated through the GitHub API using stolen GitHub tokens.
The attack abused trusted CI/CD workflows by embedding obfuscated payloads that executed during automated build processes.
a threat actor used dummy accounts and forged author identities... infected commits all feature a hardcoded date of Sept. 17, 2001, and fake bot identities, ci-bot@automated.dev or build-system@noreply.dev.
a separate "Megalodon" campaign that injected malicious GitHub Actions workflows to harvest CI/CD secrets and cloud credentials in public repositories
Analysis revealed credential harvesting capabilities targeting GitHub tokens, cloud credentials, API keys, database secrets, and private keys.
The incident... involved thousands of malicious commits that injected credential-stealing payloads into repositories... the stolen information included CI environment variables, AWS credentials, Google Cloud Platform access tokens, Azure credentials... GitHub Actions tokens, GitLab CI/CD tokens, API keys...
It also queries AWS, Google Cloud Platform, and Azure metadata for instance role credentials, reads SSH private keys...
It also queries AWS, Google Cloud Platform, and Azure metadata for instance role credentials.
The recent wave of supply chain attacks targeting packages, extensions, and CI pipelines, such as Shai-Hulud, Megalodon and Miasma, should be read less as isolated package integrity failures and more as credential-harvesting campaigns.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Shai-Hulud-related campaign wave that poisoned repositories and CI/CD workflows at scale using mass malicious commits and follow-on package compromise.
Named malware/campaign referenced as involved in large-scale GitHub repository poisonings.
A separate campaign involving malicious GitHub Actions workflow injection to steal CI/CD secrets and cloud credentials from public repositories.
A separate campaign involving malicious GitHub Actions workflow injection to steal CI/CD secrets and cloud credentials from public repositories.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.