Get all your news in one place.
100's of premium titles.
One app.
Start reading
TechRadar
TechRadar
Sead Fadilpašić

GitHub hit with another major attack — Megalodon hits over 5,000 repos with malware-laden commits

A pink triangle with a red exclamation mark inside on a blue digital landscape.
  • SafeDep researchers uncovered Megalodon, a TeamPCP‑inspired campaign infecting over 5,500 GitHub repositories with an infostealer targeting CI/CD secrets
  • The worm‑like attack spreads via malicious commits from a fake “build‑bot,” stealing cloud keys, SSH credentials, and DevOps configs, with npm packages like Tiledesk inadvertently published from poisoned repos
  • Unlike TeamPCP’s forum “competition,” Megalodon appears to be a separate copycat actor motivated by recent supply‑chain attacks, posing risks to both maintainers and downstream users

It seems we’ve gotten our first TeamPCP copycat, and it’s called Megalodon.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.