A fake bot just infected over 5,500 GitHub repositories and the developers let it in themselves.
Someone pushed malicious code disguised as an automated update under the name of a trusted build bot.
Once inside a project, it stole that project’s secrets: API keys, credentials, access tokens for cloud and other IT services, and then it used those to move into the next repo, and the next, and so on.
Researchers are calling it Megalodon.
The infection was so widespread it eventually hit a legitimate piece of software before it was identified and remediated, and one compromised project became 5,500.
You might not write software, but your team might well do. So, what are you going to do to improve the trust of your development pipeline?
#cybersecurity #supplychain #GitHub
Someone pushed malicious code disguised as an automated update under the name of a trusted build bot.
Once inside a project, it stole that project’s secrets: API keys, credentials, access tokens for cloud and other IT services, and then it used those to move into the next repo, and the next, and so on.
Researchers are calling it Megalodon.
The infection was so widespread it eventually hit a legitimate piece of software before it was identified and remediated, and one compromised project became 5,500.
You might not write software, but your team might well do. So, what are you going to do to improve the trust of your development pipeline?
#cybersecurity #supplychain #GitHub
- Category
- Cybersecurity
- Tags
- #cybersecurity #supplychain #GitHub

Comments