Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos

2026-05-26T20:51:43Zfbe38ff50ccec534c8e5e1d8b0ef14208dfd3cd1c72fa830cdac9936e87b74ba
CI/CDExchange-zero-dayMegalodonShai-HuludTeamPCPcredential-theftdeveloper-secretsgithubmalicious-commitsmalwarerepository-compromisesupply-chain-attack

What happened

A fast-moving malware campaign dubbed “Megalodon” pushed thousands of malicious commits to GitHub — compromising over 5,500 repositories in roughly six hours to harvest credentials, developer secrets and other sensitive artifacts. The activity heightens software supply-chain and CI/CD risk (stolen tokens/secrets can be reused to access cloud services, internal repos and build pipelines). Related reporting also highlights other large-scale repo incidents (GitHub breach, TeamPCP attribution) and an Exchange zero-day (CVE-2026-42897) in the same timeframe, underscoring elevated attacker activity;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
fbe38ff50ccec534c8e5e1d8b0ef14208dfd3cd1c72fa830cdac9936e87b74ba
Enrichment time
2026-05-26T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos · Baitaphish