
We're tracking "Megalodon"
An active supply chain attack injecting malicious steps into GitHub Actions workflows at scale.
575K+ files stolen. 449 GB exfiltrated. Still ongoing.
If you see 'Optimize-Build' in CI, rotate every secret immediately.
ossprey.com/blog/megalodon…
English















