Megalodon: Mass GitHub Repo Backdooring via CI Workflows
Megalodon is a novel supply chain attack technique that exploits GitHub Actions CI workflows to backdoor multiple repositories at scale. By compromising CI pipeline configurations, attackers can inject malicious code into build processes across many repos simultaneously, posing a critical risk to the software supply chain. This method bypasses traditional security controls by abusing trusted CI automation.