Automated 'Megalodon' Campaign Spreads GitHub Repo Backdoors

Summary

A stored summary is not available for this item yet.

Why It Matters for Texas Credit Unions

Original Source Material

Supply-Chain Attack Uses Malicious GitHub Actions Workflow File to Steal Secrets More than 5,000 GitHub repositories fell victim to an automated campaign, codenamed "Megalodon," in which an attacker injected malicious GitHub Actions that executed a script designed to steal development environment secrets, plus a variety of keys, tokens and other credentials, researchers said.