Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
The Hacker News
2 months ago

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

By info@thehackernews.com (The Hacker News)

Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window. "Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that exfiltrate CI

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.