Corpus graph previewActor to Incident
Supply Chain GraphPan, zoom, and select actor, campaign, and incident tiers.

Supply Chain graph is loading. Keyboard controls become available after graph initialization.

Supply Chain Incident

Focused Graph View

The persistent graph is framed to this incident while the canonical page heading and details continue below.

270 nodes467 edgesCold links hydrate here

Supply Chain Incident

Megalodon GitHub Actions repository workflow poisoning campaign

The Megalodon campaign inserted malicious GitHub Actions workflows into thousands of public repositories to harvest CI/CD secrets and cloud credentials through automated commit activity.

ConfidenceHigh
Evidence LevelResearcher
Attack StageSource Compromise
Source Artifact DivergenceNo
Attribution ConfidenceSuspected

Affected Packages

No structured records.

Affected Releases

No structured records.

Repositories

No structured records.

Organizations

No structured records.

Maintainers

No structured records.

Threat Actors

Campaigns

Build Systems

  • GitHub Actions

Distribution Channels

  • GitHub repositories

Compromised Accounts

  • repository automation commit identities

Connected Entities

Attribution Evidence

References