The Megalodon supply chain attack poisoned over 5,500 GitHub repositories via automated commits injecting GitHub Actions workflows.
Researchers say the campaign abused compromised access tokens and deploy keys to inject malicious GitHub Actions workflows ...