Megalodon GitHub Supply Chain Attack Compromised 5,500+ Repositories in Hours
A massive GitHub supply chain attack named Megalodon compromised more than 5,500 repositories in under six hours by injecting malicious CI/CD workflows into GitHub Actions pipelines. Attackers used fake automated bot accounts and disguised commits to silently deploy credential-stealing backdoors.


The malware harvested AWS, Azure, GCP, SSH, Docker, Kubernetes, npm, and GitHub credentials while abusing OIDC tokens for cloud identity impersonation. One of the most serious downstream impacts involved the compromise of the Tiledesk repository, where poisoned workflows were later propagated to npm package releases.
Security experts recommend immediately auditing GitHub workflow files, rotating exposed secrets, reviewing suspicious workflow executions, and pinning GitHub Actions to specific commit SHAs. NPAV DLP solutions help organizations detect malicious CI/CD activity, block suspicious connections, and prevent credential theft from supply chain attacks.
Data Loss Prevention (DLP) – Prevents leakage of cloud tokens, API keys, SSH keys, and sensitive credentials.
- Other (43)
- Ransomware (179)
- Events and News (28)
- Features (45)
- Security (505)
- Tips (83)
- Google (49)
- Achievements (13)
- Products (37)
- Activation (7)
- Dealers (1)
- Bank Phishing (61)
- Malware Alerts (301)
- Cyber Attack (384)
- Data Backup (16)
- Data Breach (232)
- Phishing (194)
- Securty Tips (9)
- Browser Hijack (30)
- Adware (15)
- Email And Password (90)
- Android Security (98)
- Knoweldgebase (37)
- Botnet (20)
- Updates (12)
- Alert (72)
- Hacking (90)
- Social Media (11)
- vulnerability (135)
- Hacker (107)
- Spyware (18)
- Windows (31)
- Microsoft (48)
- Uber (1)
- YouTube (4)
- Trojan (7)
- Website hacks (17)
- Paytm (1)
- Credit card scam (4)
- Telegram (9)
- RAT (12)
- Bug (5)
- Twitter (3)
- Facebook (14)
- Banking Trojan (17)
- Mozilla (2)
- COVID-19 (5)
- Instagram (5)
- NPAV Announcement (18)
- IoT Security (4)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- Amazon (5)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (5)
- Cloud malware (5)
- Cloud storage (2)
- Financial fraud (115)
- Impersonation phishing (4)
- DDoS (12)
- Smishing (2)
- Whale (0)
- Whale phishing (6)
- WINRAR (3)
- ZIP (2)
- Fraud Protector (101)
-
Mobile Frauds
(80)
- WhatsApp (21)
- AI (42)
- Windows Patch (0)