Supply Chain Attack
Megalodon Campaign Backdoored 5,561 GitHub Repositories via Poisoned CI/CD Workflows
An automated campaign called Megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in six hours, hiding secret-stealing payloads inside CI/CD workflow files. It weaponizes the merge — the most routine action in software development.