• About
  • Advertise
  • Privacy & Policy
  • Contact
Vidianews
  • Home
  • Entertainment
    • All
    • Gaming
    • Movie
    pope-leo-warns-that-artificial-intelligence-could-threaten-humanity

    Pope Leo warns that artificial intelligence could threaten humanity

    sydney-sweeney-goes-completely-topless-in-wild-‘euphoria’-scene

    Sydney Sweeney goes completely topless in wild ‘Euphoria’ scene

    the-last-of-us:-powerlines-is-an-official-new-release-for-serious-fans

    The Last Of Us: Powerlines is an official new release for serious fans

    r-type-dimensions-iii-gives-great-classic-look-and-bad-hitboxes

    R-Type Dimensions III Gives Great Classic Look And Bad Hitboxes

    francesca-scorsese-applauds-haters-for-cruel-comments

    Francesca Scorsese applauds haters for cruel comments

    alec-baldwin’s-daughter-ireland-expecting-second-baby-with-rac

    Alec Baldwin’s Daughter Ireland Expecting Second Baby With RAC

  • Sports
  • Tech
    • All
    • Gadget
    • Startup
    github-hit-by-another-major-attack

    GitHub hit by another major attack

    digital-spring-cleaning-is-now-a-frontline-defense-in-the-fraud-economy

    Digital Spring Cleaning Is Now a Frontline Defense in the Fraud Economy

    Pope Leo’s encyclical on AI has arrived. He offers wisdom to big tech, governments and you

    does-your-internet-keep-its-promises?-vote-for-the-people’s-picks-awards-2026

    Does your Internet keep its promises? Vote for the People’s Picks Awards 2026

    these-privacy-conscious-gay-dating-apps-want-to-dethrone-grindr

    These privacy-conscious gay dating apps want to dethrone Grindr

    6-kitchen-gadgets-that-make-adult-life-easier-|-techcrunch

    6 kitchen gadgets that make adult life easier | TechCrunch

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Lifestyle
    • All
    • Faith
    • Health
    • Travel
    smarter-engagement-for-stronger-growth:-how-payers-can-do-more-with-less-–-medcity-news

    Smarter Engagement for Stronger Growth: How Payers Can Do More with Less – MedCity News

    remembrance-day-guide

    Remembrance Day Guide

    bobbi-brown’s-rules-for-summer-beauty

    Bobbi Brown’s Rules for Summer Beauty

    prayer-for-god’s-grace:-rest-in-his-glorious-gift

    Prayer for God’s Grace: Rest in His Glorious Gift

    summer-is-for-book-lovers:-readers-share-their-favorites

    Summer is for book lovers: readers share their favorites

    how-to-remove-sunscreen-from-clothes:-what-actually-works-|-live-better

    How To Remove Sunscreen From Clothes: What Actually Works | Live Better

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • News
    • All
    • Business
    • Science

    Anti-Semitism not contained in Australia after Gaza war, intelligence chief says

    ai-wealth-must-benefit-public,-says-s.-korean-vice-prime-minister-amid-samsung-labor-tensions

    AI wealth must benefit public, says S. Korean vice prime minister amid Samsung labor tensions

    potential-crack-on-toxic-chemical-tank-in-california-could-ease-pressure-as-authorities-race-to-prevent-explosion

    Potential crack on toxic chemical tank in California could ease pressure as authorities race to prevent explosion

    oil-prices-fall-amid-hopes-for-us-iran-peace-deal

    Oil prices fall amid hopes for US-Iran peace deal

    Trump tells US negotiators ‘don’t rush’ into Iran deal

    How Saudi Arabia’s spending spree reached its end

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Business
  • Politics
  • World
  • Review

    MacBook Pro’s OLED panels will enter mass production next month as planned launch nears: report

    Mark Zuckerberg is not always a colorless automaton

    Meta launches Forum app as Reddit-like platform for discussions with AI-powered assistant for admins

    Are smartphone launches during the coronavirus pandemic making things worse?

    Hide Your Number on WhatsApp: How to Set a Username for Better Privacy

    OnePlus 8 and OnePlus 8 Pro launch impressions: Are they too expensive to succeed in India?

No Result
View All Result
  • Home
  • Entertainment
    • All
    • Gaming
    • Movie
    pope-leo-warns-that-artificial-intelligence-could-threaten-humanity

    Pope Leo warns that artificial intelligence could threaten humanity

    sydney-sweeney-goes-completely-topless-in-wild-‘euphoria’-scene

    Sydney Sweeney goes completely topless in wild ‘Euphoria’ scene

    the-last-of-us:-powerlines-is-an-official-new-release-for-serious-fans

    The Last Of Us: Powerlines is an official new release for serious fans

    r-type-dimensions-iii-gives-great-classic-look-and-bad-hitboxes

    R-Type Dimensions III Gives Great Classic Look And Bad Hitboxes

    francesca-scorsese-applauds-haters-for-cruel-comments

    Francesca Scorsese applauds haters for cruel comments

    alec-baldwin’s-daughter-ireland-expecting-second-baby-with-rac

    Alec Baldwin’s Daughter Ireland Expecting Second Baby With RAC

  • Sports
  • Tech
    • All
    • Gadget
    • Startup
    github-hit-by-another-major-attack

    GitHub hit by another major attack

    digital-spring-cleaning-is-now-a-frontline-defense-in-the-fraud-economy

    Digital Spring Cleaning Is Now a Frontline Defense in the Fraud Economy

    Pope Leo’s encyclical on AI has arrived. He offers wisdom to big tech, governments and you

    does-your-internet-keep-its-promises?-vote-for-the-people’s-picks-awards-2026

    Does your Internet keep its promises? Vote for the People’s Picks Awards 2026

    these-privacy-conscious-gay-dating-apps-want-to-dethrone-grindr

    These privacy-conscious gay dating apps want to dethrone Grindr

    6-kitchen-gadgets-that-make-adult-life-easier-|-techcrunch

    6 kitchen gadgets that make adult life easier | TechCrunch

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Lifestyle
    • All
    • Faith
    • Health
    • Travel
    smarter-engagement-for-stronger-growth:-how-payers-can-do-more-with-less-–-medcity-news

    Smarter Engagement for Stronger Growth: How Payers Can Do More with Less – MedCity News

    remembrance-day-guide

    Remembrance Day Guide

    bobbi-brown’s-rules-for-summer-beauty

    Bobbi Brown’s Rules for Summer Beauty

    prayer-for-god’s-grace:-rest-in-his-glorious-gift

    Prayer for God’s Grace: Rest in His Glorious Gift

    summer-is-for-book-lovers:-readers-share-their-favorites

    Summer is for book lovers: readers share their favorites

    how-to-remove-sunscreen-from-clothes:-what-actually-works-|-live-better

    How To Remove Sunscreen From Clothes: What Actually Works | Live Better

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • News
    • All
    • Business
    • Science

    Anti-Semitism not contained in Australia after Gaza war, intelligence chief says

    ai-wealth-must-benefit-public,-says-s.-korean-vice-prime-minister-amid-samsung-labor-tensions

    AI wealth must benefit public, says S. Korean vice prime minister amid Samsung labor tensions

    potential-crack-on-toxic-chemical-tank-in-california-could-ease-pressure-as-authorities-race-to-prevent-explosion

    Potential crack on toxic chemical tank in California could ease pressure as authorities race to prevent explosion

    oil-prices-fall-amid-hopes-for-us-iran-peace-deal

    Oil prices fall amid hopes for US-Iran peace deal

    Trump tells US negotiators ‘don’t rush’ into Iran deal

    How Saudi Arabia’s spending spree reached its end

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Business
  • Politics
  • World
  • Review

    MacBook Pro’s OLED panels will enter mass production next month as planned launch nears: report

    Mark Zuckerberg is not always a colorless automaton

    Meta launches Forum app as Reddit-like platform for discussions with AI-powered assistant for admins

    Are smartphone launches during the coronavirus pandemic making things worse?

    Hide Your Number on WhatsApp: How to Set a Username for Better Privacy

    OnePlus 8 and OnePlus 8 Pro launch impressions: Are they too expensive to succeed in India?

No Result
View All Result
Vidianews
No Result
View All Result
Home Tech

GitHub hit by another major attack

Ivan Mehta by Ivan Mehta
May 25, 2026
in Tech
0
github-hit-by-another-major-attack

GitHub hit by another major attack

0
SHARES
0
VIEWS
Share on FacebookShare on Twitter
A pink triangle with a red exclamation mark inside on a blue digital landscape
(Image credit: Getty Images)

  • SafeDep researchers discovered Megalodon, a TeamPCP-inspired campaign infecting over 5,500 GitHub repositories with an information stealer targeting CI/CD secrets.
  • The worm attack spreads via malicious commits from a fake “build bot”, stealing cloud keys, SSH credentials and DevOps configurations, with npm packages like Tiledesk inadvertently released from poisoned repositories.
  • Unlike TeamPCP’s “competition” forum, Megalodon appears to be a separate copycat actor motivated by recent supply chain attacks, posing risks to both maintainers and downstream users.

It looks like we’ve gotten our first TeamPCP copycat, and it’s called Megalodon.

Late last week, security researchers SafeDep reported discovering more than 5,500 GitHub repositories infected with an information stealer that scrapes all kinds of secrets from victim developers’ CI/CD pipeline.

In a detailed report published on its blog, SafeDep explained that the attack begins with the submission of a malicious commit. The malicious actor, named “build-bot,” pretended to be a robot that submits automated commits. If these commits, containing the infostealer, are accepted by the maintainer, they collect all kinds of secrets before spreading to other repositories like a classic worm.

Among other things, Megalodon has been observed scraping AWS secret keys and Google Cloud access tokens, instance role credentials from AWS, GCP, and Azure, SSH private keys, Docker and Kubernetes configurations, Vault tokens, Terraform credentials, and more.

Push to npm

At this point in the attack, the only people at risk are GitHub maintainers. However, if they move their repositories to npm, which many do, end users can also be compromised. SafeDep detailed how this scenario happened to Tiledesk officials:

“Versions 2.18.6 (May 19) through 2.18.12 (May 21) all carry the backdoor. The same npm account, eljohnny (giovanni@tiledesk.com), released both the clean 2.18.5 and the compromised version. The attacker never touched the npm account. He compromised the GitHub repository and the maintainer released from the poisoned source without realize it.”

In its article, The Register states that TeamPCP, the threat actor now known for targeting GitHub and npm, recently launched a “supply chain attack competition” on the Breach forums, but emphasized that Megalodon was likely not part of that competition.

Sign up for the TechRadar Pro newsletter to get all the top news, opinions, features and tips your business needs to succeed!

Instead, it appears to be an entirely separate threat actor, simply motivated by TeamPCP’s activities to launch its own malicious campaign.

The full list of compromised repositories can be found at this link.

Via The register


Best Antivirus Software

Google logo on black background next to the text “Click to follow TechRadar”

Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.


Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). During his career, which spans more than a decade, he has written for numerous media outlets, including Al Jazeera Balkans. He has also hosted several modules on content writing for Represent Communications.

Related

Ivan Mehta

Ivan Mehta

Stay Connected

  • 99 Subscribers
  • Trending
  • Comments
  • Latest
european-markets-in-mixed-territory-after-a-positive-start

European markets in mixed territory after a positive start

January 26, 2026
daniel-duggan:-australian-citizen-and-former-us-navy-pilot-loses-extradition-appeal

Daniel Duggan: Australian citizen and former US Navy pilot loses extradition appeal

April 16, 2026
12-sweet-feminine-aesthetic-outfits-for-the-summer-season

12 Sweet Feminine Aesthetic Outfits for the Summer Season

March 13, 2026
how-to-remove-blood-from-clothes:-what-actually-works-|-live-better

How To Remove Blood From Clothes: What Actually Works | Live Better

April 17, 2026
hansmaker-presents-the-d1-ultra:-a-dual-laser-engraver-designed-for-each-material-–-techenger

Hansmaker presents the D1 Ultra: a dual laser engraver designed for each material – Techenger

0
nascar-driver-denny-hamlin-breaks-silence-after-father-dies-in-house-fire

NASCAR driver Denny Hamlin breaks silence after father dies in house fire

0
fivio-foreign-checks-himself-into-a-$10,000-rehab-center-to-get-his-mind-straight

Fivio Foreign checks himself into a $10,000 rehab center to get his mind straight

0
david-beckham-leaves-brooklyn-for-his-2025-instagram-tribute-amid-family-feud

David Beckham leaves Brooklyn for his 2025 Instagram tribute amid family feud

0
github-hit-by-another-major-attack

GitHub hit by another major attack

May 25, 2026
digital-spring-cleaning-is-now-a-frontline-defense-in-the-fraud-economy

Digital Spring Cleaning Is Now a Frontline Defense in the Fraud Economy

May 25, 2026

Pope Leo’s encyclical on AI has arrived. He offers wisdom to big tech, governments and you

May 25, 2026
does-your-internet-keep-its-promises?-vote-for-the-people’s-picks-awards-2026

Does your Internet keep its promises? Vote for the People’s Picks Awards 2026

May 25, 2026

Recent News

github-hit-by-another-major-attack

GitHub hit by another major attack

May 25, 2026
digital-spring-cleaning-is-now-a-frontline-defense-in-the-fraud-economy

Digital Spring Cleaning Is Now a Frontline Defense in the Fraud Economy

May 25, 2026

Pope Leo’s encyclical on AI has arrived. He offers wisdom to big tech, governments and you

May 25, 2026
does-your-internet-keep-its-promises?-vote-for-the-people’s-picks-awards-2026

Does your Internet keep its promises? Vote for the People’s Picks Awards 2026

May 25, 2026
Vidianews

Trusted news coverage delivering accurate reporting, breaking headlines, and insightful analysis on global events, business, politics, and tech.

Follow Us

Browse by Category

  • Business
  • Entertainment
  • Faith
  • Gadget
  • Gaming
  • General
  • Health
  • Lifestyle
  • Movie
  • News
  • Politics
  • Review
  • Science
  • Sports
  • Startup
  • Tech
  • Travel
  • World

Recent News

github-hit-by-another-major-attack

GitHub hit by another major attack

May 25, 2026
digital-spring-cleaning-is-now-a-frontline-defense-in-the-fraud-economy

Digital Spring Cleaning Is Now a Frontline Defense in the Fraud Economy

May 25, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© © Copyrights 2026 Vidianews. All Rights Reserved. Designed by Vidianews

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result

© © Copyrights 2026 Vidianews. All Rights Reserved. Designed by Vidianews

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
Go to mobile version