Megalodon: automated CI/CD workflow injection backdoors 5,561 GitHub repos, propagates to @tiledesk/tiledesk-server on npm
On 2026-05-18 an automated campaign nicknamed Megalodon pushed 5,718 commits to 5,561 public GitHub repos in six hours, injecting GitHub Actions workflows that exfiltrate CI secrets to 216.126.225.129:8443. The legitimate Tiledesk maintainer then released @tiledesk/tiledesk-server 2.18.6–2.18.12 from the poisoned source - propagating the backdoor to every downstream npm install.
Versions named here: 2.18.6, 2.18.7, 2.18.8, 2.18.9, 2.18.10, 2.18.11, 2.18.12