Megalodon: Mass GitHub Repo Backdooring via CI Workflows
Safedep disclosed "Megalodon," a technique to mass-backdoor GitHub repositories by compromising CI workflows via stolen OAuth tokens or GitHub App keys, enabling malicious code pushes across an organization undetected.