Megalodon attacks GitHub, infecting more than 5,500 repositories with malicious code

Megalodon attacks GitHub, infecting more than 5,500 repositories with malicious code

70 hardware

Cyberattack on GitHub: malicious app Megalodon infects thousands of repositories

*Event date:* Monday, May 18

*Target of the attack:* GitHub development platform

*Scope of impact:* more than 5,500 repositories

What happened?
For about six hours on May 18, the malicious app Megalodon made “malicious” commits to over 5,561 repositories on GitHub. If a project owner includes such a commit, it automatically runs malicious code on CI/CD servers (Continuous Integration / Continuous Deployment). This allows attackers to quickly spread the program within the project's infrastructure.

How does Megalodon work?
1. Theft of CI/CD credentials

- AWS secret keys, Google Cloud and Azure tokens

- Metadata of cloud provider instances

- Closed SSH keys, Docker/Kubernetes configurations

- Vault tokens, Terraform credentials

2. Source code scanning

- Uses more than 30 regular expressions to find hidden tokens and keys.

3. Acquisition of GitHub tokens

- Including authentication tokens for cloud providers and Bitbucket, enabling attackers to impersonate developers and gain access to cloud services.

Where was it first discovered?
Malicious code appeared in the open platform Tiledesk – an online chat and chatbot system.

- The project administrator published a “clean” version 2.18.5, but then approved versions from 2.18.6 (May 19) to 2.18.12 (May 21), which contained backdoors.

Connection with hacker group
- Similar schemes are used by the TeamPCP group.

- However, there is no direct confirmation of their involvement in the Megalodon campaign.

- TeamPCP announced a contest for supply‑chain attacks, but participants must add an encryption public key to the code; the creator of Megalodon is likely not one of them.

Tracking activity
Researchers traced the malicious code’s activity to two email addresses.

- Using them, commits were sent to 5,561 repositories.

- All changes appeared on May 18 within a little over six hours.

Conclusion
Regular GitHub breaches threaten the security of any company, even if its repositories are private. Malicious software continues to infiltrate infrastructure and has not yet been fully stopped from spreading.

Comments (0)

Share your thoughts — please be polite and stay on topic.

No comments yet. Leave a comment — share your opinion!

To leave a comment, please log in.

Log in to comment