Vulnerabilità · 127 giorni fa
Un commit di workflow malevolo in GitHub Actions non è un problema che riguarda solo il repository. Può trasformare CI in un sifone di credenziali che estrae secret memorizzati, dati di ambiente a breve durata del runner, credenziali dei metadati cloud, chiavi SSH e token OIDC che raggiungono altri sistemi cloud e SaaS dopo che il repository stesso è stato patchato.
4 fonti che coprono questa storia
Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos
In just six hours, the campaign quietly pushed malware to more than 5,500 GitHub repositories, stealing credentials, developer secrets, and more.
GitHub Actions abused by Megalodon attack to slip malicious commits into 5,500 repos
Researchers say the campaign abused compromised access tokens and deploy keys to inject malicious GitHub Actions workflows into thousands of public repositories.
Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack
Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens.
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
Megalodon pushed 5,718 malicious GitHub commits in 6 hours, exposing CI secrets and cloud credentials at scale.
Part of the PlainSec briefing for 2026-05-26