Megalodon chums the waters in 5.5K+ GitHub repo poisonings
2026-05-22T19:23:57Z•c96d7ac07f503a3a04ba0646a6401107eaaf527ea5a8a159e1ed68ac7ec45b73
ai-sandboxapi-keysbug-bountycode-exfiltrationcode-signingcredential-leakcritical-patchdrupalgithublinux-kernelmacos‑stealernginxnpmplaintext-passwordsprivilege-escalationransomwarerepo-poisoningsecrets-exposuresupply-chainvs-code-extension
What happened
This feed aggregates multiple, high-impact security incidents and trends: a large-scale supply‑chain poisoning campaign (Megalodon) that affected 5.5K+ GitHub repos and related poisoned VS Code extensions that reportedly led to exfiltration of internal GitHub repos; several npm/poisoning incidents (Shai‑Hulud, TanStack) and downstream supply‑chain malware; high‑risk vendor/device flaws (Cisco Secure Workload admin bug, NGINX Rift being probed/exploited days after disclosure, a Linux kernel privilege escalation, and a critically urgent Drupal core patch); widespread credential and secret leaks/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- c96d7ac07f503a3a04ba0646a6401107eaaf527ea5a8a159e1ed68ac7ec45b73
- Enrichment time
- 2026-05-22T19:23:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.