Megalodon chums the waters in 5.5K+ GitHub repo poisonings

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A threat actor dubbed 'Megalodon' has poisoned over 5,500 GitHub repositories in a supply chain attack campaign. The operation targets developers and CI/CD pipelines by injecting malicious code into public repositories, posing significant risks to anyone cloning or depending on affected projects.

5m read timeFrom theregister.com
Post cover image
Table of contents
Malicious code is still reaching their servers, and nothing is stopping it before it doesnpm … but not TeamPCPWho is built-bot?GitHub says internal repos exfiltrated after poisoned VS Code extension attackShai-Hulud copycat worm infects yet another npm packageTanStack weighs invitation-only pull requests after supply chain attackTwo different attackers poisoned popular open source tools - and showed us the future of supply chain compromise
94.8K Impressions1 Comment