Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos
2026-05-26T20:51:43Z•fbe38ff50ccec534c8e5e1d8b0ef14208dfd3cd1c72fa830cdac9936e87b74ba
CI/CDExchange-zero-dayMegalodonShai-HuludTeamPCPcredential-theftdeveloper-secretsgithubmalicious-commitsmalwarerepository-compromisesupply-chain-attack
What happened
A fast-moving malware campaign dubbed “Megalodon” pushed thousands of malicious commits to GitHub — compromising over 5,500 repositories in roughly six hours to harvest credentials, developer secrets and other sensitive artifacts. The activity heightens software supply-chain and CI/CD risk (stolen tokens/secrets can be reused to access cloud services, internal repos and build pipelines). Related reporting also highlights other large-scale repo incidents (GitHub breach, TeamPCP attribution) and an Exchange zero-day (CVE-2026-42897) in the same timeframe, underscoring elevated attacker activity;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- fbe38ff50ccec534c8e5e1d8b0ef14208dfd3cd1c72fa830cdac9936e87b74ba
- Enrichment time
- 2026-05-26T20:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.