Last Updated: 2026-05-21T20:32:38Z
What’s Happening
A widespread GitHub Actions attack codenamed “Megalodon” has compromised over 5600 GitHub repos. The payload is an infostealer that of course has worming capabilities.
SafeDep has the details.
Actions
Review the commit messages, users, and contents for presence in your repositories. Also note the exfiltration server at 216.126.225[.]129:8443, although these connections will likely be made from a GitHub Actions VM, unless you’re using custom runners. If so, watch those for suspicious activity.