# Megalodon GitHub Actions Supply Chain Campaign — 5,561 Repositories Compromised, @tiledesk/tiledesk-server npm Backdoor (CI Credential Harvester)

> Between 11:36-17:48 UTC on 2026-05-18, an automated supply chain campaign codenamed 'Megalodon' pushed 5,718 malicious commits to 5,561 GitHub repositories, injecting two GitHub Actions workflow variants ('SysDiag' mass and 'Optimize-Build' targeted) that beacon to 216.126.225.129:8443 and exfiltrate CI environment variables, AWS/GCP/Azure cloud credentials, OIDC tokens, SSH keys, and developer secrets. Downstream compromise of Tiledesk's release pipeline propagated the backdoor into npm releases @tiledesk/tiledesk-server 2.18.6-2.18.12. Discovered by SafeDep's Malysis engine.

- **Published:** 2026-05-21T12:00:00Z
- **Last reviewed:** 2026-05-21T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0556
- **ID:** TL-2026-0556
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

## Overview

Megalodon is a six-hour, fully automated GitHub Actions supply chain campaign observed on 2026-05-18 in which throwaway GitHub accounts pushed 5,718 malicious commits across 5,561 public repositories, embedding two distinct GitHub Actions workflow variants that exfiltrate CI environment secrets and short-lived cloud credentials to a single hard-coded C2 endpoint (216.126.225.129:8443). The campaign was discovered by SafeDep's Malysis engine after the base64-encoded payload was bundled into an npm release of @tiledesk/tiledesk-server (a popular open-source customer support / messaging server), confirming downstream propagation from the GitHub Actions worm into the public npm ecosystem.

## Attack Chain

**1. Resource development.** The operator(s) provisioned a fleet of throwaway GitHub accounts whose usernames follow a randomized 8-character pattern, paired with two boilerplate commit author identities (build-system@noreply.dev / ci-bot@automated.dev) and four rotating author display names (build-bot, auto-ci, ci-bot, pipeline-bot). A single dedicated VPS at 216.126.225.129 was stood up on TCP/8443 to receive exfiltration traffic.

**2. Initial access via workflow injection.** Targeted repositories were selected en masse (likely via GitHub code search and language filters). For each repo, the worm pushed a malicious commit whose message imitated routine CI hygiene work — 'ci: add build optimization step' or 'chore: optimize pipeline runtime' — to evade casual review. Two workflow variants were observed:

- **SysDiag (mass variant)** — written to `.github/workflows/ci.yml`, triggered on `push` and `pull_request_target`. The `pull_request_target` trigger is critical because it runs with the base repository's secrets and write tokens even when fired by an untrusted fork PR, a recurring high-severity GitHub Actions footgun.
- **Optimize-Build (targeted variant)** — uses `workflow_dispatch` so the workflow lies dormant and is only triggered manually by the attacker on chosen victims. This gives Megalodon on-demand re-entry into the victim's CI without producing noisy automatic runs.

**3. Elevated permission grant.** Both variants explicitly request `permissions: id-token: write` and `actions: read`. The id-token write capability is what lets the workflow mint a GitHub OIDC ID token that can be exchanged for short-lived cloud credentials in AWS (`sts:AssumeRoleWithWebIdentity`), GCP (Workload Identity Federation), and Azure (federated credentials) — i.e. cloud identity impersonation without ever needing a long-lived secret in the repo.

**4. Payload execution.** Each workflow embeds a base64-encoded bash payload (~111 lines decoded) that performs:

- Enumeration of every `env` variable in the Actions runner, plus `/proc/*/environ` and PID 1 environment data to capture secrets injected by parent processes.
- Collection of all AWS access keys, secret keys, and session tokens from every configured profile (`~/.aws/credentials`, `~/.aws/config`).
- Queries of cloud instance metadata services: AWS IMDSv2, GCP metadata, Azure IMDS to lift instance role credentials.
- `gcloud auth print-access-token` to obtain GCP user / service-account tokens.
- Minting of a GitHub OIDC token via the `ACTIONS_ID_TOKEN_REQUEST_URL` / `ACTIONS_ID_TOKEN_REQUEST_TOKEN` runner variables, POSTed alongside the harvested bundle so the operator can later impersonate the repo's federated cloud identity.
- Collection of SSH private keys (`~/.ssh/id_*`), Docker auth configs (`~/.docker/config.json`), `.npmrc`, `.netrc`, Kubernetes kubeconfigs, Vault tokens, and Terraform credentials.
- A source-tree grep across 30+ regex patterns matching generic API keys, JWTs, PEM-encoded private keys, database connection strings, and known cloud-provider token formats (AWS AKIA*, ASIA*, Google AIza*, GitHub ghp_*, Slack xox*).

**5. Exfiltration.** All collected secrets are bundled and POSTed over TLS to `https://216.126.225.129:8443/`. The use of a raw IP plus a high port avoids reliance on disposable DNS infrastructure and removes the latency of domain takedown.

**6. npm propagation (Tiledesk).** Tiledesk's own release pipeline ran a compromised workflow, which caused the obfuscated payload to be embedded inside the bundled artifact published to npm. Versions 2.18.6 through 2.18.12 of `@tiledesk/tiledesk-server` ship with the payload, turning every CI/CD pipeline that installs Tiledesk into a downstream victim of the same credential harvester — a textbook case of a CI-borne worm crossing ecosystem boundaries from GitHub Actions into npm.

## Impact

- 5,561 GitHub repositories carry at least one Megalodon commit; many are dependencies of other projects, so the actual cloud-credential blast radius is materially larger than the headline repo count.
- Any organization that ran a Megalodon-poisoned workflow with `id-token: write` between 11:36 UTC and ~18:30 UTC on 2026-05-18 must assume their federated AWS/GCP/Azure roles (and any role those roles can chain to) are compromised. OIDC tokens are short-lived but their exchanged STS / SA credentials can persist for hours.
- All organizations consuming `@tiledesk/tiledesk-server@>=2.18.6 <=2.18.12` from npm must treat every secret available to their build agent — including production deploy credentials — as exposed.

## Attribution

No confirmed nation-state attribution. The combination of mass automation, ecosystem-agnostic credential targeting, a single hard-coded C2, and the inclusion of OIDC token theft for cloud impersonation is consistent with financially-motivated supply chain operators (cryptojacking / cloud-resource fraud / extortion) rather than espionage actors, who typically prefer narrower, lower-noise targeting. Attribution confidence: LOW.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1585 Establish Accounts
- T1587 Develop Capabilities
- T1586 Compromise Accounts
- T1195 Supply Chain Compromise
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1546 Event Triggered Execution
- T1505 Server Software Component
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036 Masquerading
- T1685 Disable or Modify Tools
- T1552 Unsecured Credentials
- T1528 Steal Application Access Token
- T1555 Credentials from Password Stores
- T1083 File and Directory Discovery
- T1580 Cloud Infrastructure Discovery
- T1057 Process Discovery
- T1005 Data from Local System
- T1119 Automated Collection
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1571 Non-Standard Port
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1496 Resource Hijacking

## Sources

- [Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours](https://cybersecuritynews.com/megalodon-malware-github-repos/)
- [SafeDep Malysis — Megalodon Campaign Analysis](https://safedep.io/research/megalodon-github-actions-supply-chain)
- [GitHub Security Lab — pull_request_target Security Considerations](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/)
- [GitHub Docs — Configuring OpenID Connect in cloud providers](https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/about-security-hardening-with-openid-connect)
- [MITRE ATT&CK — T1195.002 Supply Chain Compromise: Software Supply Chain](https://attack.mitre.org/techniques/T1195/002/)
- [MITRE ATT&CK — T1552.001 Unsecured Credentials: Credentials In Files](https://attack.mitre.org/techniques/T1552/001/)
- [MITRE ATT&CK — T1528 Steal Application Access Token](https://attack.mitre.org/techniques/T1528/)
- [CISA — Defending Continuous Integration / Continuous Delivery (CI/CD) Pipelines](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-178a)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0556
