WeSearch

The "Megalodon" Campaign: 5718 malicious commits to 5561 GitHub repos

Β· 0 reactions Β· 0 comments Β· 11 views
The "Megalodon" Campaign: 5718 malicious commits to 5561 GitHub repos

🚨 The "π™ΌπšŽπšπšŠπš•πš˜πšπš˜πš—" Campaign is live... 𝟻,𝟽𝟷𝟾 malicious commits to 𝟻,𝟻𝟼𝟷 GitHub repositories in a six-hour window. Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected π™Άπš’πšπ™·πšžπš‹ π™°πšŒπšπš’πš˜πš—πšœ workflows containing πš‹πšŠπšœπšŽπŸΌπŸΊ-πšŽπš—πšŒπš˜πšπšŽπš bash payloads that exfiltrate: - CI secrets, - cloud credentials - SSH keys - OIDC tokens - source code secrets Check your repo / Technical details: https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/

Original article
Nitter
Read full at Nitter β†’
Anonymous Β· no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from Nitter