Megalodon: 5,561 GitHub Repos Backdoored via Infostealer-Sourced CI Credentials
How campaign Megalodon weaponized infostealer-harvested developer secrets to backdoor 5,561 GitHub repositories in automated CI runs.
On May 18, 2026 between 11:36 a.m. and 5:48 p.m. UTC, an automated campaign dubbed Megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a single six-hour window. A follow-up investigation by Hudson Rock published May 23 concluded the attack was exclusively sourced from infostealer-compromised credentials, with over 33% of affected GitHub accounts directly matching computers in known infostealer logs.
Attack Chain
The attacker rotated through four forged author identities — build-bot, auto-ci, ci-bot, pipeline-bot — and seven commit messages mimicking routine CI maintenance. Throwaway GitHub accounts with randomised 8-character usernames (e.g., rkb8el9r, bhlru9nr) were used to push via compromised PATs or deploy keys.
The injected payload was a Base64-encoded bash script embedded in a new .github/workflows/ file. Two payload variants were observed:
- SysDiag — mass variant; adds a workflow triggered on every
pushandpull_request. - Optimize-Build — targeted variant; triggers only on
workflow_dispatchto avoid CI pipeline spam and reduce noise for operational security.
Once a repository owner merges the commit, the malware executes inside the CI/CD runner and exfiltrates:
- AWS, GCP, and Azure credentials (including IMDSv2/metadata service tokens)
- SSH private keys
- GitHub Actions OIDC tokens and
GITHUB_TOKEN - GitLab CI/CD and Bitbucket tokens
- Docker and Kubernetes configs, Vault tokens, Terraform credentials
.envfiles,credentials.json,service-account.json- API keys, database connection strings, JWTs, PEM private keys (matched via 30+ regex patterns)
- Shell history and
/proc/*/environ
All collected data was exfiltrated to a C2 server at 216.126.225[.]129:8443.
Infostealer Root Cause
Hudson Rock's May 23 analysis confirmed that the affected GitHub accounts were "exclusively sourced from infostealer data." 331 of 978 unique usernames directly matched computers infected by infostealers. Even where usernames didn't directly overlap, associated email addresses revealed further stealer compromises. The attack is therefore a downstream consequence of the broader infostealer epidemic rather than a GitHub platform vulnerability.
npm Fallout and Polymarket Drainer
npm responded by invalidating all granular access tokens with write access that could bypass 2FA, and urged maintainers to switch to Trusted Publishing. In a separate but related incident, nine malicious npm packages impersonating Polymarket trading CLI tools were published within a 30-second window to steal Ethereum/Polygon private keys via a postinstall hook that POSTs raw keys to a Cloudflare Worker at hxxps://polymarketbot.polymarketdev.workers[.]dev/v1/wallets/keys.
IOCs
- C2:
216.126.225[.]129:8443 - Forged author names:
build-bot,auto-ci,ci-bot,pipeline-bot - npm wallet drainer C2:
polymarketbot.polymarketdev.workers[.]dev
Remediation
- Rotate all GitHub PATs, deploy keys, and any secrets that may have been present in CI environments since May 18.
- Audit your
.github/workflows/directory for unexpected files added by unknown contributors. - Enable required reviewers on pull requests that touch workflow files.
- Enforce Trusted Publishing for npm packages instead of long-lived token-based publishing.
- Run
git log --all --author="build-bot\|auto-ci\|ci-bot\|pipeline-bot" --onelineto find injected commits. - Hunt infostealer exposure via HaveIBeenPwned, Hudson Rock Cavalier, or SpyCloud across all developer email addresses.
← Back to the Security Roundup: Week of May 28, 2026