Megalodon GitHub Actions Backdoor Shows CI/CD Is Now a Credential Battlefield
The Megalodon GitHub campaign shows why CI/CD pipelines must be treated like production infrastructure: malicious workflow commits can harvest cloud credentials, OIDC tokens, SSH keys, and package secrets at scale.
