Threat reportSupply ChainTL-2026-0556

Megalodon GitHub Actions Supply Chain Campaign — 5,561 Repositories Compromised, @tiledesk/tiledesk-server npm Backdoor (CI Credential Harvester)

criticalACTIVE

Megalodon GitHub Actions Supply Chain Campaign (TL-2026-0556), also tracked as Megalodon, is a critical-severity supply-chain compromise, first published 2026-05-21. It has no confirmed attribution, affects Tiledesk @tiledesk/tiledesk-server (npm), maps to 29 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
29MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-0556

Threat ID
TL-2026-0556
Also known as
Megalodon, Megalodon GitHub Actions Worm, Tiledesk npm Supply Chain Compromise
Severity
CRITICAL
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, software-development, open-source, saas, cloud-services, devops
Target regions
Global
Detection rules
9
Indicators of compromise
28

Malware and tooling in Megalodon GitHub Actions Supply Chain Campaign

Malware and tooling: Megalodon

How Megalodon GitHub Actions Supply Chain Campaign works

Between 11:36-17:48 UTC on 2026-05-18, an automated supply chain campaign codenamed 'Megalodon' pushed 5,718 malicious commits to 5,561 GitHub repositories, injecting two GitHub Actions workflow variants ('SysDiag' mass and 'Optimize-Build' targeted) that beacon to 216.126.225.129:8443 and exfiltrate CI environment variables, AWS/GCP/Azure cloud credentials, OIDC tokens, SSH keys, and developer secrets. Downstream compromise of Tiledesk's release pipeline propagated the backdoor into npm releases @tiledesk/tiledesk-server 2.18.6-2.18.12. Discovered by SafeDep's Malysis engine.

## Overview

Megalodon is a six-hour, fully automated GitHub Actions supply chain campaign observed on 2026-05-18 in which throwaway GitHub accounts pushed 5,718 malicious commits across 5,561 public repositories, embedding two distinct GitHub Actions workflow variants that exfiltrate CI environment secrets and short-lived cloud credentials to a single hard-coded C2 endpoint (216.126.225.129:8443). The campaign was discovered by SafeDep's Malysis engine after the base64-encoded payload was bundled into an npm release of @tiledesk/tiledesk-server (a popular open-source customer support / messaging server), confirming downstream propagation from the GitHub Actions worm into the public npm ecosystem.

## Attack Chain

**1. Resource development.** The operator(s) provisioned a fleet of throwaway GitHub accounts whose usernames follow a randomized 8-character pattern, paired with two boilerplate commit author identities (build-system@noreply.dev / ci-bot@automated.dev) and four rotating author display names (build-bot, auto-ci, ci-bot, pipeline-bot). A single dedicated VPS at 216.126.225.129 was stood up on TCP/8443 to receive exfiltration traffic.

**2. Initial access via workflow injection.** Targeted repositories were selected en masse (likely via GitHub code search and language filters). For each repo, the worm pushed a malicious commit whose message imitated routine CI hygiene work — 'ci: add build optimization step' or 'chore: optimize pipeline runtime' — to evade casual review. Two workflow variants were observed:

- **SysDiag (mass variant)** — written to `.github/workflows/ci.yml`, triggered on `push` and `pull_request_target`. The `pull_request_target` trigger is critical because it runs with the base repository's secrets and write tokens even when fired by an untrusted fork PR, a recurring high-severity GitHub Actions footgun. - **Optimize-Build (targeted variant)** — uses `workflow_dispatch` so the workflow lies dormant and is only triggered manually by the attacker on chosen victims. This gives Megalodon on-demand re-entry into the victim's CI without producing noisy automatic runs.

**3. Elevated permission grant.** Both variants explicitly request `permissions: id-token: write` and `actions: read`. The id-token write capability is what lets the workflow mint a GitHub OIDC ID token that can be exchanged for short-lived cloud credentials in AWS (`sts:AssumeRoleWithWebIdentity`), GCP (Workload Identity Federation), and Azure (federated credentials) — i.e. cloud identity impersonation without ever needing a long-lived secret in the repo.

**4. Payload execution.** Each workflow embeds a base64-encoded bash payload (~111 lines decoded) that performs:

- Enumeration of every `env` variable in the Actions runner, plus `/proc/*/environ` and PID 1 environment data to capture secrets injected by parent processes. - Collection of all AWS access keys, secret keys, and session tokens from every configured profile (`~/.aws/credentials`, `~/.aws/config`). - Queries of cloud instance metadata services: AWS IMDSv2, GCP metadata, Azure IMDS to lift instance role credentials. - `gcloud auth print-access-token` to obtain GCP user / service-account tokens. - Minting of a GitHub OIDC token via the `ACTIONS_ID_TOKEN_REQUEST_URL` / `ACTIONS_ID_TOKEN_REQUEST_TOKEN` runner variables, POSTed alongside the harvested bundle so the operator can later impersonate the repo's federated cloud identity. - Collection of SSH private keys (`~/.ssh/id_*`), Docker auth configs (`~/.docker/config.json`), `.npmrc`, `.netrc`, Kubernetes kubeconfigs, Vault tokens, and Terraform credentials. - A source-tree grep across 30+ regex patterns matching generic API keys, JWTs, PEM-encoded private keys, database connection strings, and known cloud-provider token formats (AWS AKIA*, ASIA*, Google AIza*, GitHub ghp_*, Slack xox*).

**5. Exfiltration.** All collected secrets are bundled and POSTed over TLS to `https://216.126.225.129:8443/`. The use of a raw IP plus a high port avoids reliance on disposable DNS infrastructure and removes the latency of domain takedown.

**6. npm propagation (Tiledesk).** Tiledesk's own release pipeline ran a compromised workflow, which caused the obfuscated payload to be embedded inside the bundled artifact published to npm. Versions 2.18.6 through 2.18.12 of `@tiledesk/tiledesk-server` ship with the payload, turning every CI/CD pipeline that installs Tiledesk into a downstream victim of the same credential harvester — a textbook case of a CI-borne worm crossing ecosystem boundaries from GitHub Actions into npm.

## Impact

- 5,561 GitHub repositories carry at least one Megalodon commit; many are dependencies of other projects, so the actual cloud-credential blast radius is materially larger than the headline repo count. - Any organization that ran a Megalodon-poisoned workflow with `id-token: write` between 11:36 UTC and ~18:30 UTC on 2026-05-18 must assume their federated AWS/GCP/Azure roles (and any role those roles can chain to) are compromised. OIDC tokens are short-lived but their exchanged STS / SA credentials can persist for hours. - All organizations consuming `@tiledesk/tiledesk-server@>=2.18.6 <=2.18.12` from npm must treat every secret available to their build agent — including production deploy credentials — as exposed.

## Attribution

No confirmed nation-state attribution. The combination of mass automation, ecosystem-agnostic credential targeting, a single hard-coded C2, and the inclusion of OIDC token theft for cloud impersonation is consistent with financially-motivated supply chain operators (cryptojacking / cloud-resource fraud / extortion) rather than espionage actors, who typically prefer narrower, lower-noise targeting. Attribution confidence: LOW.

MITRE ATT&CK techniques used in TL-2026-0556

Collection

T1005 Data from Local System; T1119 Automated Collection

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Discovery

T1057 Process Discovery; T1083 File and Directory Discovery; T1580 Cloud Infrastructure Discovery

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573 Encrypted Channel

Initial Access

T1078 Valid Accounts; T1195 Supply Chain Compromise

Impact

T1496 Resource Hijacking

Persistence

T1505 Server Software Component; T1546 Event Triggered Execution

Credential Access

T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts; T1587 Develop Capabilities

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Megalodon GitHub Actions Supply Chain Campaign

  • Tiledesk — @tiledesk/tiledesk-server (npm)
    Vulnerable versions: 2.18.6; 2.18.7; 2.18.8; 2.18.9; 2.18.10; 2.18.11; 2.18.12
  • GitHub — GitHub Actions (workflow trust model)
    Vulnerable versions: all
  • Community — 5,561 public GitHub repositories (identified by SafeDep)
    Vulnerable versions: any branch containing commit acac5a9854650c4ae2883c4740bf87d34120c038 or equivalent SysDiag/Optimize-Build workflow

Remediation for Megalodon GitHub Actions Supply Chain Campaign

Patches

  • Tiledesk: install only @tiledesk/tiledesk-server versions outside the 2.18.6-2.18.12 range; await a vendor-issued clean release with provenance.
  • GitHub: no platform patch available — this abuses documented Actions features; mitigation is policy-level.

Immediate actions

  • Block egress to 216.126.225.129 (all ports, especially TCP/8443) at perimeter firewalls, EDR/network sensors, and cloud VPC NACLs.
  • Audit every GitHub Actions run between 2026-05-18T11:36Z and 2026-05-18T19:00Z for workflow files matching `.github/workflows/ci.yml` modified by unknown author identities (build-bot, auto-ci, ci-bot, pipeline-bot, build-system@noreply.dev, ci-bot@automated.dev).
  • Revert or revoke commit acac5a9854650c4ae2883c4740bf87d34120c038 wherever present and force-push history to remove it from default branches.
  • Rotate every secret that was available to a Megalodon-poisoned runner: GitHub Actions repository/organization secrets, AWS IAM access keys, AWS STS session tokens issued via OIDC, GCP service-account keys and short-lived OIDC tokens, Azure federated credentials, npm publish tokens, Docker registry credentials, SSH deploy keys, Vault tokens, and any Terraform state credentials.
  • Quarantine and remove @tiledesk/tiledesk-server versions 2.18.6, 2.18.7, 2.18.8, 2.18.9, 2.18.10, 2.18.11, and 2.18.12 from internal registries and lockfiles. Pin to 2.18.5 or wait for a clean post-2.18.12 release.
  • Inspect cloud audit logs (AWS CloudTrail, GCP Cloud Audit Logs, Azure Activity Log) for `AssumeRoleWithWebIdentity`, federated-token, and identity-impersonation events sourced from GitHub Actions runners during and after the campaign window.

Workarounds

  • Where rapid policy change is infeasible, set repository-level `permissions: contents: read` at the workflow root and explicitly opt in to `id-token: write` only in the narrow job that needs it.
  • Force `pull_request_target` workflows to check out the PR head with `actions/checkout` only after manual approval, and never run code from the PR head when secrets are exposed.

Longer-term hardening

  • Disallow the `pull_request_target` trigger combined with `id-token: write` in all org-wide GitHub Actions policies; allow it only via explicit per-repo exception with reviewed reusable workflows.
  • Enable GitHub Actions 'Required workflows' / 'Allowed actions' policies at the organization level so unreviewed third-party actions cannot run.
  • Replace long-lived cloud keys in CI with OIDC federation that is narrowly scoped per workflow path AND per branch (sub claim conditions), so a malicious workflow on a non-release branch cannot mint production credentials.
  • Deploy a workflow-file integrity monitor (e.g., GitHub branch protection requiring code review on `.github/workflows/**`, plus an out-of-band repo audit) to detect unauthorized workflow additions.
  • Adopt npm package provenance / Sigstore attestations and enforce them at install time so unsigned or non-attested releases are rejected by build agents.
  • Implement egress allowlisting on self-hosted Actions runners so beacons to arbitrary IPs (e.g., raw 216.126.225.129:8443) fail closed.

Weaknesses (CWE) in Megalodon GitHub Actions Supply Chain Campaign

CWE-506, CWE-829, CWE-494, CWE-1357, CWE-1395

Timeline of Megalodon GitHub Actions Supply Chain Campaign

  • 17:48 UTC — Mass-push activity ceases after 5,718 malicious commits across 5,561 repositories. Some Optimize-Build (workflow_dispatch) variants remain dormant for on-demand re-entry.
  • Compromised Tiledesk build pipeline executes a Megalodon workflow during a routine release, embedding the obfuscated payload into the npm artifact for @tiledesk/tiledesk-server (subsequently propagated through versions 2.18.6-2.18.12).
  • 11:36 UTC — First Megalodon commit observed on GitHub; throwaway accounts begin pushing SysDiag / Optimize-Build workflow injections at high volume.
  • SafeDep pivots from the npm payload to GitHub and identifies the 5,561-repo mass-injection campaign, correlating commit metadata, workflow content, and shared C2 endpoint.
  • SafeDep's Malysis engine flags the base64-encoded payload embedded in a bundled workflow file inside @tiledesk/tiledesk-server@2.18.12, surfacing the npm-side compromise.
  • SafeDep publishes preliminary campaign analysis naming the campaign 'Megalodon', documenting the SysDiag / Optimize-Build variants and C2 at 216.126.225.129:8443.
  • Threadlinqs Intelligence publishes TL-2026-0556 with full MITRE mapping, IOC set, detections, and simulation guidance.
  • Cyber Security News publishes a public summary of the Megalodon campaign citing SafeDep's findings.
  • As of 2026-05-29, Megalodon remains active: it is now attributed to TeamPCP/UNC6780, whose 20+ supply-chain waves (npm/PyPI/GitHub Actions, GitHub internal breach, Mini Shai-Hulud) continued through late May. Dormant workflow_dispatch backdoors persist, C2 216.126.225.129 has no confirmed takedown, and no clean Tiledesk release past 2.18.12 exists.

Sources cited for Megalodon GitHub Actions Supply Chain Campaign

Detection coverage for TL-2026-0556

As of 2026-05-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0556 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats