Cybersecurity researchers have revealed details of a new automated campaign dubbed Megalodonthat pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window. Using temporary accounts and fake author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that extracted CI secrets, cloud credentials, SSH keys, OIDC tokens, and source code secrets to a C2 server at 216.126.225[.]129:8443.
See also: GitHub faces a battle for survival at Microsoft

The full list of data collected by the malware includes: CI environment variables, /proc/*/environ , and environment PID 1 , Amazon Web Services (AWS) credentials , Google Cloud access tokens , instance role credentials obtained through queries to AWS IMDSv2 , Google Cloud metadata and Microsoft Azure Instance Metadata Service (IMDS) endpoints, Docker and Kubernetes settings, Terraform credentials, API keys, database connection strings, JWTs, PEM private keys and cloud tokens matching over 30 secret regular expression patterns, OIDC GitHub Actions token request URL and token, GITHUB_TOKEN , GitLab CI/CD tokens and Bitbucket tokens, .env files, credentials.json, service-account.json and other configuration files.
One of the affected packages is @tiledesk/tiledesk-server, which includes a Base64-encoded bash payload inside a GitHub Actions workflow file.
A total of 5,718 commits were pushed to 5,561 separate repositories on May 18, 2026, between 11:36 AM and 5:48 PM UTC. The attacker alternated between four author names (build-bot, auto-ci, ci-bot, pipeline-bot) and seven commit messages, all mimicking CI maintenance routines. The attacker used temporary GitHub accounts with random 8-character usernames (e.g., rkb8el9r, bhlru9nr, lo6wt4t6), configured git config to spoof the author's identity, and pushed via compromised PATs or development keys.
See also: GitHub confirms breach of ~3,800 internal repos – What dev teams should do

Two payload variants have been observed as part of the large-scale campaign: SysDiag, a bulk variant that adds a new workflow that is triggered on every push and pull request, and Optimize-Build, a targeted variant that is only triggered on workflow_dispatch, a GitHub Actions trigger that allows users to manually run a workflow on demand. In the case of Tiledesk, the targeted approach is used to target CI/CD runners, rather than when the npm package is installed.
The trade-off is reach: on push would guarantee execution on every commit to master, hitting more targets without intervention. Workflow_dispatch sacrifices this for operational security. With over 5,700 repositories compromised, even a small percentage yielding a usable GITHUB_TOKEN gives the attacker enough targets to trigger on demand. The result is that once a repository owner merges the commit, the malware is executed within their CI/CD workflows and propagates further, allowing for the theft of credentials and secrets at scale.
“We have entered a new era of supply chain attacks, and TeamPCP’s GitHub breach was just the beginning,” said Moshe Siman Tov Bustan of OX Security. “What follows is an endless wave, a tsunami of cyberattacks on developers worldwide.” The development comes as TeamPCP has weaponized the interconnected software supply chain to corrupt hundreds of open source tools, infiltrating various ecosystems and extorting victims for profit in some cases.
Microsoft-owned GitHub has become the latest addition to the group's long list of victims, which also includes TanStack, Grafana Labs, OpenAI , and Mistral AI.
See also: GitHub investigates breach by TeamPCP

TeamPCP's attacks have fueled a vicious cycle of exploiting popular open source projects, where one breach feeds the next, allowing the malware to spread like wildfire in a worm-like manner. The group also appears to be financially motivated, and has formed partnerships with BreachForums and other extortion groups such as LAPSUS$ and VECT.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
