Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos
2026-05-27T02:51:41Z•2c4fb6a0d7425f28ac8f061c02f6e6a0764c7fe82cd1fe98cdb7ae48be6e3f38
APTCVE-2026-42897Cisco-SD-WANClaw-ChainOT-securityOpenClawShai-HuludSharePointTeamPCPUnderminrapi-keyscredentials-theftdomain-frontinggit-repo-tamperinggithubmalwaremegalodonroboticssupply-chainzero-day
What happened
Dark Reading roundup highlights a high-impact campaign (Megalodon) that pushed thousands of malicious commits to 5,500+ GitHub repositories in hours to steal credentials and developer secrets, alongside related supply-chain and repo-tampering threats (TeamPCP, Shai-Hulud). The feed also flags multiple actively exploited and critical vulnerabilities — including a Microsoft Exchange OWA zero-day (CVE-2026-42897), an out-of-band SharePoint patch, a critical command-injection flaw in an OT robot OS, and a CVSS 10.0 Cisco SD‑WAN bug — plus cloud key/secret issues (Google API keys remaining active),
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 2c4fb6a0d7425f28ac8f061c02f6e6a0764c7fe82cd1fe98cdb7ae48be6e3f38
- Enrichment time
- 2026-05-27T02:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.