←── back to feed
/topics/megalodon-github-repo-poisoning-attack

Megalodon GitHub repo poisoning attack

5 items2 sourcesupdated 24d agotrend 0

A hacker group called TeamPCP conducted a large-scale supply chain attack dubbed Megalodon, poisoning over 5,500 GitHub repositories through malicious CI workflows, postinstall hooks, and merge queue corruption. The attack affected hundreds of Node.js projects and other open source code, marking one of the largest coordinated repository compromises on record.