Megalodon: Mass GitHub Repo Backdooring via CI Workflows
Megalodon is a mass backdooring technique that exploits GitHub CI workflows to compromise repositories at scale. By injecting malicious steps into CI pipelines, attackers can gain persistent access to exposed GitHub tokens and secrets across multiple repos. This method poses a critical supply chain security risk, as CI workflows are typically granted broad permissions.