Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos

2026-05-27T02:51:41Z2c4fb6a0d7425f28ac8f061c02f6e6a0764c7fe82cd1fe98cdb7ae48be6e3f38
APTCVE-2026-42897Cisco-SD-WANClaw-ChainOT-securityOpenClawShai-HuludSharePointTeamPCPUnderminrapi-keyscredentials-theftdomain-frontinggit-repo-tamperinggithubmalwaremegalodonroboticssupply-chainzero-day

What happened

Dark Reading roundup highlights a high-impact campaign (Megalodon) that pushed thousands of malicious commits to 5,500+ GitHub repositories in hours to steal credentials and developer secrets, alongside related supply-chain and repo-tampering threats (TeamPCP, Shai-Hulud). The feed also flags multiple actively exploited and critical vulnerabilities — including a Microsoft Exchange OWA zero-day (CVE-2026-42897), an out-of-band SharePoint patch, a critical command-injection flaw in an OT robot OS, and a CVSS 10.0 Cisco SD‑WAN bug — plus cloud key/secret issues (Google API keys remaining active),

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
2c4fb6a0d7425f28ac8f061c02f6e6a0764c7fe82cd1fe98cdb7ae48be6e3f38
Enrichment time
2026-05-27T02:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos · Baitaphish