Threat reportSupply ChainTL-2026-0556
Megalodon GitHub Actions Supply Chain Campaign — 5,561 Repositories Compromised, @tiledesk/tiledesk-server npm Backdoor (CI Credential Harvester)
Megalodon GitHub Actions Supply Chain Campaign (TL-2026-0556), also tracked as Megalodon, is a critical-severity supply-chain compromise, first published 2026-05-21. It has no confirmed attribution, affects Tiledesk @tiledesk/tiledesk-server (npm), maps to 29 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 29MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-0556
- Threat ID
- TL-2026-0556
- Also known as
- Megalodon, Megalodon GitHub Actions Worm, Tiledesk npm Supply Chain Compromise
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, open-source, saas, cloud-services, devops
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in Megalodon GitHub Actions Supply Chain Campaign
Malware and tooling: Megalodon
How Megalodon GitHub Actions Supply Chain Campaign works
Between 11:36-17:48 UTC on 2026-05-18, an automated supply chain campaign codenamed 'Megalodon' pushed 5,718 malicious commits to 5,561 GitHub repositories, injecting two GitHub Actions workflow variants ('SysDiag' mass and 'Optimize-Build' targeted) that beacon to 216.126.225.129:8443 and exfiltrate CI environment variables, AWS/GCP/Azure cloud credentials, OIDC tokens, SSH keys, and developer secrets. Downstream compromise of Tiledesk's release pipeline propagated the backdoor into npm releases @tiledesk/tiledesk-server 2.18.6-2.18.12. Discovered by SafeDep's Malysis engine.
## Overview
Megalodon is a six-hour, fully automated GitHub Actions supply chain campaign observed on 2026-05-18 in which throwaway GitHub accounts pushed 5,718 malicious commits across 5,561 public repositories, embedding two distinct GitHub Actions workflow variants that exfiltrate CI environment secrets and short-lived cloud credentials to a single hard-coded C2 endpoint (216.126.225.129:8443). The campaign was discovered by SafeDep's Malysis engine after the base64-encoded payload was bundled into an npm release of @tiledesk/tiledesk-server (a popular open-source customer support / messaging server), confirming downstream propagation from the GitHub Actions worm into the public npm ecosystem.
## Attack Chain
**1. Resource development.** The operator(s) provisioned a fleet of throwaway GitHub accounts whose usernames follow a randomized 8-character pattern, paired with two boilerplate commit author identities (build-system@noreply.dev / ci-bot@automated.dev) and four rotating author display names (build-bot, auto-ci, ci-bot, pipeline-bot). A single dedicated VPS at 216.126.225.129 was stood up on TCP/8443 to receive exfiltration traffic.
**2. Initial access via workflow injection.** Targeted repositories were selected en masse (likely via GitHub code search and language filters). For each repo, the worm pushed a malicious commit whose message imitated routine CI hygiene work — 'ci: add build optimization step' or 'chore: optimize pipeline runtime' — to evade casual review. Two workflow variants were observed:
- **SysDiag (mass variant)** — written to `.github/workflows/ci.yml`, triggered on `push` and `pull_request_target`. The `pull_request_target` trigger is critical because it runs with the base repository's secrets and write tokens even when fired by an untrusted fork PR, a recurring high-severity GitHub Actions footgun. - **Optimize-Build (targeted variant)** — uses `workflow_dispatch` so the workflow lies dormant and is only triggered manually by the attacker on chosen victims. This gives Megalodon on-demand re-entry into the victim's CI without producing noisy automatic runs.
**3. Elevated permission grant.** Both variants explicitly request `permissions: id-token: write` and `actions: read`. The id-token write capability is what lets the workflow mint a GitHub OIDC ID token that can be exchanged for short-lived cloud credentials in AWS (`sts:AssumeRoleWithWebIdentity`), GCP (Workload Identity Federation), and Azure (federated credentials) — i.e. cloud identity impersonation without ever needing a long-lived secret in the repo.
**4. Payload execution.** Each workflow embeds a base64-encoded bash payload (~111 lines decoded) that performs:
- Enumeration of every `env` variable in the Actions runner, plus `/proc/*/environ` and PID 1 environment data to capture secrets injected by parent processes. - Collection of all AWS access keys, secret keys, and session tokens from every configured profile (`~/.aws/credentials`, `~/.aws/config`). - Queries of cloud instance metadata services: AWS IMDSv2, GCP metadata, Azure IMDS to lift instance role credentials. - `gcloud auth print-access-token` to obtain GCP user / service-account tokens. - Minting of a GitHub OIDC token via the `ACTIONS_ID_TOKEN_REQUEST_URL` / `ACTIONS_ID_TOKEN_REQUEST_TOKEN` runner variables, POSTed alongside the harvested bundle so the operator can later impersonate the repo's federated cloud identity. - Collection of SSH private keys (`~/.ssh/id_*`), Docker auth configs (`~/.docker/config.json`), `.npmrc`, `.netrc`, Kubernetes kubeconfigs, Vault tokens, and Terraform credentials. - A source-tree grep across 30+ regex patterns matching generic API keys, JWTs, PEM-encoded private keys, database connection strings, and known cloud-provider token formats (AWS AKIA*, ASIA*, Google AIza*, GitHub ghp_*, Slack xox*).
**5. Exfiltration.** All collected secrets are bundled and POSTed over TLS to `https://216.126.225.129:8443/`. The use of a raw IP plus a high port avoids reliance on disposable DNS infrastructure and removes the latency of domain takedown.
**6. npm propagation (Tiledesk).** Tiledesk's own release pipeline ran a compromised workflow, which caused the obfuscated payload to be embedded inside the bundled artifact published to npm. Versions 2.18.6 through 2.18.12 of `@tiledesk/tiledesk-server` ship with the payload, turning every CI/CD pipeline that installs Tiledesk into a downstream victim of the same credential harvester — a textbook case of a CI-borne worm crossing ecosystem boundaries from GitHub Actions into npm.
## Impact
- 5,561 GitHub repositories carry at least one Megalodon commit; many are dependencies of other projects, so the actual cloud-credential blast radius is materially larger than the headline repo count. - Any organization that ran a Megalodon-poisoned workflow with `id-token: write` between 11:36 UTC and ~18:30 UTC on 2026-05-18 must assume their federated AWS/GCP/Azure roles (and any role those roles can chain to) are compromised. OIDC tokens are short-lived but their exchanged STS / SA credentials can persist for hours. - All organizations consuming `@tiledesk/tiledesk-server@>=2.18.6 <=2.18.12` from npm must treat every secret available to their build agent — including production deploy credentials — as exposed.
## Attribution
No confirmed nation-state attribution. The combination of mass automation, ecosystem-agnostic credential targeting, a single hard-coded C2, and the inclusion of OIDC token theft for cloud impersonation is consistent with financially-motivated supply chain operators (cryptojacking / cloud-resource fraud / extortion) rather than espionage actors, who typically prefer narrower, lower-noise targeting. Attribution confidence: LOW.
MITRE ATT&CK techniques used in TL-2026-0556
Collection
T1005 Data from Local System; T1119 Automated Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Discovery
T1057 Process Discovery; T1083 File and Directory Discovery; T1580 Cloud Infrastructure Discovery
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573 Encrypted Channel
Initial Access
T1078 Valid Accounts; T1195 Supply Chain Compromise
Impact
Persistence
T1505 Server Software Component; T1546 Event Triggered Execution
Credential Access
T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts; T1587 Develop Capabilities
defense-impairment
Affected products and versions in Megalodon GitHub Actions Supply Chain Campaign
- Tiledesk — @tiledesk/tiledesk-server (npm)
Vulnerable versions: 2.18.6; 2.18.7; 2.18.8; 2.18.9; 2.18.10; 2.18.11; 2.18.12 - GitHub — GitHub Actions (workflow trust model)
Vulnerable versions: all - Community — 5,561 public GitHub repositories (identified by SafeDep)
Vulnerable versions: any branch containing commit acac5a9854650c4ae2883c4740bf87d34120c038 or equivalent SysDiag/Optimize-Build workflow
Remediation for Megalodon GitHub Actions Supply Chain Campaign
Patches
- Tiledesk: install only @tiledesk/tiledesk-server versions outside the 2.18.6-2.18.12 range; await a vendor-issued clean release with provenance.
- GitHub: no platform patch available — this abuses documented Actions features; mitigation is policy-level.
Immediate actions
- Block egress to 216.126.225.129 (all ports, especially TCP/8443) at perimeter firewalls, EDR/network sensors, and cloud VPC NACLs.
- Audit every GitHub Actions run between 2026-05-18T11:36Z and 2026-05-18T19:00Z for workflow files matching `.github/workflows/ci.yml` modified by unknown author identities (build-bot, auto-ci, ci-bot, pipeline-bot, build-system@noreply.dev, ci-bot@automated.dev).
- Revert or revoke commit acac5a9854650c4ae2883c4740bf87d34120c038 wherever present and force-push history to remove it from default branches.
- Rotate every secret that was available to a Megalodon-poisoned runner: GitHub Actions repository/organization secrets, AWS IAM access keys, AWS STS session tokens issued via OIDC, GCP service-account keys and short-lived OIDC tokens, Azure federated credentials, npm publish tokens, Docker registry credentials, SSH deploy keys, Vault tokens, and any Terraform state credentials.
- Quarantine and remove @tiledesk/tiledesk-server versions 2.18.6, 2.18.7, 2.18.8, 2.18.9, 2.18.10, 2.18.11, and 2.18.12 from internal registries and lockfiles. Pin to 2.18.5 or wait for a clean post-2.18.12 release.
- Inspect cloud audit logs (AWS CloudTrail, GCP Cloud Audit Logs, Azure Activity Log) for `AssumeRoleWithWebIdentity`, federated-token, and identity-impersonation events sourced from GitHub Actions runners during and after the campaign window.
Workarounds
- Where rapid policy change is infeasible, set repository-level `permissions: contents: read` at the workflow root and explicitly opt in to `id-token: write` only in the narrow job that needs it.
- Force `pull_request_target` workflows to check out the PR head with `actions/checkout` only after manual approval, and never run code from the PR head when secrets are exposed.
Longer-term hardening
- Disallow the `pull_request_target` trigger combined with `id-token: write` in all org-wide GitHub Actions policies; allow it only via explicit per-repo exception with reviewed reusable workflows.
- Enable GitHub Actions 'Required workflows' / 'Allowed actions' policies at the organization level so unreviewed third-party actions cannot run.
- Replace long-lived cloud keys in CI with OIDC federation that is narrowly scoped per workflow path AND per branch (sub claim conditions), so a malicious workflow on a non-release branch cannot mint production credentials.
- Deploy a workflow-file integrity monitor (e.g., GitHub branch protection requiring code review on `.github/workflows/**`, plus an out-of-band repo audit) to detect unauthorized workflow additions.
- Adopt npm package provenance / Sigstore attestations and enforce them at install time so unsigned or non-attested releases are rejected by build agents.
- Implement egress allowlisting on self-hosted Actions runners so beacons to arbitrary IPs (e.g., raw 216.126.225.129:8443) fail closed.
Weaknesses (CWE) in Megalodon GitHub Actions Supply Chain Campaign
Timeline of Megalodon GitHub Actions Supply Chain Campaign
- 17:48 UTC — Mass-push activity ceases after 5,718 malicious commits across 5,561 repositories. Some Optimize-Build (workflow_dispatch) variants remain dormant for on-demand re-entry.
- Compromised Tiledesk build pipeline executes a Megalodon workflow during a routine release, embedding the obfuscated payload into the npm artifact for @tiledesk/tiledesk-server (subsequently propagated through versions 2.18.6-2.18.12).
- 11:36 UTC — First Megalodon commit observed on GitHub; throwaway accounts begin pushing SysDiag / Optimize-Build workflow injections at high volume.
- SafeDep pivots from the npm payload to GitHub and identifies the 5,561-repo mass-injection campaign, correlating commit metadata, workflow content, and shared C2 endpoint.
- SafeDep's Malysis engine flags the base64-encoded payload embedded in a bundled workflow file inside @tiledesk/tiledesk-server@2.18.12, surfacing the npm-side compromise.
- SafeDep publishes preliminary campaign analysis naming the campaign 'Megalodon', documenting the SysDiag / Optimize-Build variants and C2 at 216.126.225.129:8443.
- Threadlinqs Intelligence publishes TL-2026-0556 with full MITRE mapping, IOC set, detections, and simulation guidance.
- Cyber Security News publishes a public summary of the Megalodon campaign citing SafeDep's findings.
- As of 2026-05-29, Megalodon remains active: it is now attributed to TeamPCP/UNC6780, whose 20+ supply-chain waves (npm/PyPI/GitHub Actions, GitHub internal breach, Mini Shai-Hulud) continued through late May. Dormant workflow_dispatch backdoors persist, C2 216.126.225.129 has no confirmed takedown, and no clean Tiledesk release past 2.18.12 exists.
Sources cited for Megalodon GitHub Actions Supply Chain Campaign
- Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours
- SafeDep Malysis — Megalodon Campaign Analysis
- GitHub Security Lab — pull_request_target Security Considerations
- GitHub Docs — Configuring OpenID Connect in cloud providers
- MITRE ATT&CK — T1195.002 Supply Chain Compromise: Software Supply Chain
- MITRE ATT&CK — T1552.001 Unsecured Credentials: Credentials In Files
- MITRE ATT&CK — T1528 Steal Application Access Token
- CISA — Defending Continuous Integration / Continuous Delivery (CI/CD) Pipelines
Detection coverage for TL-2026-0556
As of 2026-05-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0556 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.