首页 时政热点 科技头条 智能AI 安全攻防 数码硬件 开发者生态 汽车 游戏 社会热点 开源推荐 医疗健康 归档 标签 关于

Megalodon GitHub 攻击通过恶意 CI/CD 工作流程瞄准 5,561 个存储库

摘要

Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window。

bot that GitHub Cybersecurity researchers
2026-05-22 1 阅读 约1分钟阅读 info@thehackernews.com (The Hacker News)
分享:
字号:
网络安全研究人员披露了一项名为 Megalodon 的新自动化活动的详细信息,该活动在 6 小时内将 5,718 个恶意提交推送到 5,561 个 GitHub 存储库。 “攻击者使用一次性帐户和伪造的作者身份(build-bot、auto-ci、ci-bot、pipeline-bot)注入了 GitHub Actions 工作流程,其中包含可渗透 CI 的 Base64 编码的 bash 有效负载
这篇文章对您有帮助吗?

订阅66必读

每日精选科技资讯,直达你的邮箱