On 18 May 2026, in a six-hour window, an automated campaign pushed 5,718 malicious commits to 5,561 public GitHub repositories. SafeDep, which discovered it and named it Megalodon, says the commits were made with forged "build bot" identities using compromised personal access tokens or deploy keys. They added or replaced GitHub Actions workflows with an encoded bash payload that steals every secret available to a CI run: cloud credentials, SSH keys, registry tokens, Kubernetes configs, Vault tokens and GitHub Actions OIDC tokens that can be exchanged for cloud access. The campaign surfaced when the Tiledesk chatbot platform shipped backdoored npm versions built from its poisoned repository. It was the same day a separate attack pushed the malicious Nx Console extension that led to GitHub's own breach. Megalodon shows how a stolen repository credential turns a CI pipeline into a secret-harvesting machine at scale.
Key takeaways
- SafeDep counted 5,718 malicious commits across 5,561 repositories between about 11:36 and 17:48 UTC on 18 May 2026, using forged author names such as "build-bot", "auto-ci" and "ci-bot".
- The commits landed without pull requests. SafeDep says this points to compromised personal access tokens or deploy keys, and StepSecurity says repositories with weak branch protection were the target.
- Two payload variants were used: one ran on every push and pull request, and a stealthier one waited for a manual
workflow_dispatchtrigger. - The payload harvested the full CI environment, AWS, GCP and Azure credentials, SSH keys, Docker, npm, Kubernetes, Vault and Terraform credentials, and GitHub OIDC, GitLab and Bitbucket tokens, sending them to a single server.
- Tiledesk published backdoored npm versions 2.18.6 to 2.18.12 between 19 and 21 May from its poisoned source. SafeDep says the attacker never touched the npm account itself.
At a glance
| Organisations | 5,561 public GitHub repositories, including Tiledesk, Wiznet's ioLibrary_Driver, persian-tools and the Black-Iron-Project; downstream users of affected packages |
|---|---|
| When | Malicious commits on 18 May 2026 (about 11:36 to 17:48 UTC); backdoored Tiledesk npm releases 19 to 21 May 2026; reported 22 to 26 May 2026 |
| Attacker | Unattributed. OX Security notes a TeamPCP-like technique (fake historical commit dates) but no confirmed link |
| Entry point | Direct pushes to default branches using compromised personal access tokens or deploy keys, according to SafeDep |
| Identities abused | Compromised GitHub personal access tokens and deploy keys; forged bot author identities; all CI secrets and OIDC tokens available to each workflow run |
| Impact | Backdoored CI workflows in thousands of repositories; secrets exfiltrated from every affected pipeline run; backdoored npm package releases |
| Category | NHI. Incident class: confirmed NHI breach (stolen repository credentials used to steal CI secrets at scale) |
What happened
SafeDep found Megalodon while investigating Tiledesk, an open-source live chat and chatbot platform. Tiledesk's npm package versions 2.18.6 (19 May) to 2.18.12 (21 May) all carried a backdoor. Comparing them with the clean release led to a commit on 18 May authored by "build-bot <[email protected]>" with the message "ci: add build optimization step". It was pushed without a pull request or merge commit, which SafeDep says points to a compromised personal access token or deploy key. SafeDep noted: "The attacker never touched the NPM account. They compromised the GitHub repository, and the maintainer published from the poisoned source without realizing it."
Following the forged identities led to the full campaign. According to SecurityWeek, "All 5,718 commits landed on the same day: May 18, 2026, across a six-hour window from approximately 11:36 to 17:48 UTC, targeting 5,561 distinct repositories." CSO Online reports that Wiznet's ioLibrary_Driver, four Tiledesk repositories and four persian-tools repositories were among the hardest hit, with more than 2,000 malicious commits between them. OX Security describes fake automated commits with a hard-coded date of 17 September 2001, and says it confirmed more than 3,500 repositories carrying the infected workflow file.
The commits added workflows in two variants. "SysDiag" ran on every push and pull request. "Optimize-Build" replaced existing workflows and waited for a manual workflow_dispatch trigger, leaving a dormant backdoor. Both decoded a bash payload that, according to StepSecurity, dumped the CI environment and /proc/*/environ. It also collected AWS keys and session tokens, GCP OAuth tokens and Azure instance credentials; SSH keys, Docker, npm and Kubernetes configs, Vault tokens and Terraform credentials; GitHub Actions OIDC tokens, GitLab and Bitbucket CI tokens; and anything in the workspace matching more than 30 secret patterns. Everything went to a single server at 216.126.225.129 on port 8443. SafeDep advised teams using OIDC federation for cloud deployments to "review cloud audit logs for token requests from unknown workflow runs."
Timeline
| Date | Event |
|---|---|
| 18 May 2026 | 5,718 malicious commits pushed to 5,561 repositories between about 11:36 and 17:48 UTC. |
| 19 May 2026 | First backdoored Tiledesk npm version (2.18.6) published from the poisoned repository. |
| 21 May 2026 | Last backdoored Tiledesk version (2.18.12) published. |
| 22 May 2026 | StepSecurity publishes its analysis of the campaign. |
| 25 May 2026 | SecurityWeek reports the campaign, citing SafeDep. |
| 26 May 2026 | CSO Online reports on the payload variants and compromised credentials. |
How it happened: the identity attack path
- Stolen repository credentials. Compromised personal access tokens or deploy keys gave the attacker write access to thousands of repositories.
- Forged bot identities. Commits were authored as "build-bot", "auto-ci" and "ci-bot" with CI-style messages, so they blended in with genuine automation.
- No review on the default branch. Where branch protection did not require reviewed pull requests, the malicious workflows landed directly.
- CI runs with every secret loaded. Each workflow run had repository secrets, cloud credentials and, where permitted, the ability to mint OIDC tokens for cloud access.
- Harvest and exfiltrate. The payload collected those secrets and posted them to the attacker's server, with no visible failure in the workflow.
- Downstream packages poisoned. Maintainers who built from affected repositories, like Tiledesk, shipped the backdoor to their own users.
Impact
- Repositories: 5,561 affected by 5,718 commits, according to SafeDep; OX Security confirmed more than 3,500 carrying the infected workflow at the time of its analysis.
- Secrets: every secret available to affected CI runs potentially stolen, including cloud credentials and OIDC-based cloud access.
- Packages: Tiledesk npm versions 2.18.6 to 2.18.12 backdoored and passed to downstream users.
- Ecosystem: part of an intense week of supply chain attacks that also included the TanStack and Nx Console compromises.
What this means for NHI and AI agent security
Megalodon is a pure non-human identity attack. Stolen repository credentials, whether personal access tokens or deploy keys, were used under forged bot identities to modify CI configuration. The CI system then handed over every machine credential it held. No human account was phished and no vulnerability was exploited. The attack relied on credentials with write access and pipelines that trust whatever is on the default branch.
It also shows why OIDC federation is not automatically safer. Short-lived, keyless cloud access is a big improvement over static keys, but any workflow that can mint an OIDC token can be made to mint one for the attacker if the workflow itself is compromised. Cloud trust policies should be tied to specific repositories, branches and workflows, and token requests from unexpected runs should raise alerts. Our CI/CD Pipeline Identity Security Guide covers these controls, and our Shai-Hulud analysis covers the worm that set the pattern.
Recommendations
- Protect default branches. Require reviewed pull requests and code-owner approval for changes to
.github/workflows, and block direct pushes. See our CI/CD Pipeline Identity Security Guide. - Retire long-lived personal access tokens and deploy keys. Replace them with fine-grained, short-lived tokens or GitHub Apps, and revoke unused keys. See our API Key Management Guide.
- Scope OIDC trust tightly. Bind cloud roles to specific repositories, branches and workflows, and alert on token requests from unknown runs. See our Cloud Workload Identity Guide.
- Restrict runner egress. Limit where CI runners can send data, so a payload cannot post secrets to an arbitrary server.
- Hunt and rotate. Search for commits by "build-bot", "auto-ci" or "ci-bot" and traffic to 216.126.225.129, then rotate every secret available to affected workflows. Use our Leaked Credential Response Playbook.
Frequently asked questions
What was the Megalodon attack?
Megalodon was an automated campaign on 18 May 2026 that pushed 5,718 malicious commits to 5,561 GitHub repositories, adding GitHub Actions workflows that steal CI secrets. SafeDep discovered it after backdoored Tiledesk npm packages were published from a poisoned repository.
How did the attackers get write access?
SafeDep says the commits were pushed directly without pull requests, pointing to compromised personal access tokens or deploy keys. The commits used forged bot identities such as "build-bot" to look like routine automation.
What should affected projects do?
Remove the malicious workflows, check for dormant workflow_dispatch backdoors, review cloud audit logs for OIDC token requests from unknown runs, rotate every secret available to the pipeline, and revoke the tokens or keys used to push the commits.
Related NHI Mgmt Group resources
GitHub internal repositories breach 2026 · Shai-Hulud npm campaign · GitHub Action supply chain attack leaks CI/CD secrets · MemTensor supply chain attack 2026 · CI/CD Pipeline Identity Security Guide
How NHI Mgmt Group can help
Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as stolen repository tokens turn CI pipelines into secret-harvesting machines. Our NHI Foundation Level Training Course gives teams the practical grounding to lock them down.
References
- StepSecurity: Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,500+ Public Repositories (22 May 2026)
- SecurityWeek: Over 5,500 GitHub Repositories Infected in 'Megalodon' Supply Chain Attack (25 May 2026)
- CSO Online: GitHub Actions abused by Megalodon attack to slip malicious commits into 5,500 repos (26 May 2026)
- OX Security: Megalodon: New CI/CD Malware Spreads Across GitHub (21 May 2026)