π¨ The "πΌππππππππ" Campaign is live...
π»,π½π·πΎ malicious commits to π»,π»πΌπ· GitHub repositories in a six-hour window.
Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected πΆπππ·ππ π°ππππππ workflows containing πππππΌπΊ-πππππππ bash payloads that exfiltrate:
- CI secrets,
- cloud credentials
- SSH keys
- OIDC tokens
- source code secrets
Check your repo / Technical details:
safedep.io/megalodon-mass-giβ¦