Megalodon: 5,561 GitHub Repos Backdoored via Infostealer-Sourced CI Credentials

How campaign Megalodon weaponized infostealer-harvested developer secrets to backdoor 5,561 GitHub repositories in automated CI runs.

Megalodon: 5,561 GitHub Repos Backdoored via Infostealer-Sourced CI Credentials
📌
Security Roundup Series: Week of May 28, 2026 • 4 min read deep dive

On May 18, 2026 between 11:36 a.m. and 5:48 p.m. UTC, an automated campaign dubbed Megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a single six-hour window. A follow-up investigation by Hudson Rock published May 23 concluded the attack was exclusively sourced from infostealer-compromised credentials, with over 33% of affected GitHub accounts directly matching computers in known infostealer logs.

Attack Chain

The attacker rotated through four forged author identities — build-bot, auto-ci, ci-bot, pipeline-bot — and seven commit messages mimicking routine CI maintenance. Throwaway GitHub accounts with randomised 8-character usernames (e.g., rkb8el9r, bhlru9nr) were used to push via compromised PATs or deploy keys.

The injected payload was a Base64-encoded bash script embedded in a new .github/workflows/ file. Two payload variants were observed:

  • SysDiag — mass variant; adds a workflow triggered on every push and pull_request.
  • Optimize-Build — targeted variant; triggers only on workflow_dispatch to avoid CI pipeline spam and reduce noise for operational security.

Once a repository owner merges the commit, the malware executes inside the CI/CD runner and exfiltrates:

  • AWS, GCP, and Azure credentials (including IMDSv2/metadata service tokens)
  • SSH private keys
  • GitHub Actions OIDC tokens and GITHUB_TOKEN
  • GitLab CI/CD and Bitbucket tokens
  • Docker and Kubernetes configs, Vault tokens, Terraform credentials
  • .env files, credentials.json, service-account.json
  • API keys, database connection strings, JWTs, PEM private keys (matched via 30+ regex patterns)
  • Shell history and /proc/*/environ

All collected data was exfiltrated to a C2 server at 216.126.225[.]129:8443.

Infostealer Root Cause

Hudson Rock's May 23 analysis confirmed that the affected GitHub accounts were "exclusively sourced from infostealer data." 331 of 978 unique usernames directly matched computers infected by infostealers. Even where usernames didn't directly overlap, associated email addresses revealed further stealer compromises. The attack is therefore a downstream consequence of the broader infostealer epidemic rather than a GitHub platform vulnerability.

npm Fallout and Polymarket Drainer

npm responded by invalidating all granular access tokens with write access that could bypass 2FA, and urged maintainers to switch to Trusted Publishing. In a separate but related incident, nine malicious npm packages impersonating Polymarket trading CLI tools were published within a 30-second window to steal Ethereum/Polygon private keys via a postinstall hook that POSTs raw keys to a Cloudflare Worker at hxxps://polymarketbot.polymarketdev.workers[.]dev/v1/wallets/keys.

IOCs

  • C2: 216.126.225[.]129:8443
  • Forged author names: build-bot, auto-ci, ci-bot, pipeline-bot
  • npm wallet drainer C2: polymarketbot.polymarketdev.workers[.]dev

Remediation

  • Rotate all GitHub PATs, deploy keys, and any secrets that may have been present in CI environments since May 18.
  • Audit your .github/workflows/ directory for unexpected files added by unknown contributors.
  • Enable required reviewers on pull requests that touch workflow files.
  • Enforce Trusted Publishing for npm packages instead of long-lived token-based publishing.
  • Run git log --all --author="build-bot\|auto-ci\|ci-bot\|pipeline-bot" --oneline to find injected commits.
  • Hunt infostealer exposure via HaveIBeenPwned, Hudson Rock Cavalier, or SpyCloud across all developer email addresses.

← Back to the Security Roundup: Week of May 28, 2026


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther