- SafeDep researchers uncovered Megalodon, a TeamPCP‑inspired campaign infecting over 5,500 GitHub repositories with an infostealer targeting CI/CD secrets
- The worm‑like attack spreads via malicious commits from a fake “build‑bot,” stealing cloud keys, SSH credentials, and DevOps configs, with npm packages like Tiledesk inadvertently published from poisoned repos
- Unlike TeamPCP’s forum “competition,” Megalodon appears to be a separate copycat actor motivated by recent supply‑chain attacks, posing risks to both maintainers and downstream users
It seems we’ve gotten our first TeamPCP copycat, and it’s called Megalodon.