Megalodon: Mass GitHub Repo Backdooring via CI Workflows
SafeDep researchers discovered a novel attack technique called 'Megalodon' that exploits GitHub Actions CI workflows to backdoor repositories at scale. The method abuses self-hosted runners and stolen OAuth tokens to inject malicious code into CI pipelines, potentially compromising thousands of repos. The attack highlights critical supply chain security risks in CI/CD environments.