Megalodon GitHub Actions Malware
Megalodon injected malicious GitHub Actions workflows into 5,561 repositories. Here is what maintainers should audit before rotating secrets and publishing packages.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
October 4, 2026
Megalodon injected malicious GitHub Actions workflows into 5,561 repositories. Here is what maintainers should audit before rotating secrets and publishing packages.
npm CLI 11.15.0 adds staged publishing and new install-source controls. Here is what maintainers should enable, what CI should change, and what to check…
LiteSpeed says CVE-2026-48172 is being actively exploited in its user-end cPanel plugin. Hosts should update to WHM Plugin 5.3.1.0 or remove the user-end plugin…
A Packagist and GitHub supply-chain campaign used malicious postinstall hooks to fetch Linux malware from GitHub Releases. Check package.json, CI logs, and build tokens.
Laravel-Lang Composer packages were compromised through rewritten tags that run a PHP credential stealer as soon as Composer autoload is loaded.
Grafana says attackers copied two private GitHub repositories after one workflow token was missed during post-TanStack credential rotation.
CERT-UA says Ghostwriter used compromised accounts and fake Prometheus certificate lures to target Ukrainian government entities with OYSTERFRESH malware.
Check Point says Nimbus Manticore used SEO poisoning, fake software lures, and installer abuse to deploy the new MiniFast backdoor during regional conflict activity.
Europol says First VPN, a Russian-speaking cybercrime VPN, was dismantled in Operation Saffron after years of use by ransomware actors and fraud crews.