ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-05-25
▶The Wire — Daily Briefing

The Wire — Monday, May 25, 2026

The Supply Chain Is Under Siege: Two Massive Attacks Expose the Fragility of Developer Trust

3 stories analyzed

The Supply Chain Is Under Siege: Two Massive Attacks Expose the Fragility of Developer Trust

The weekend brought news that should shake every security leader's confidence in the software supply chain. We're not talking about isolated incidents anymore — we're seeing coordinated, multi-vector attacks that hit the very foundation of how modern software gets built, distributed, and deployed. And they're working.

Over the past seventy-two hours, security researchers have uncovered two separate but thematically linked campaigns that together paint a picture of adversaries thinking strategically about where maximum damage can be inflicted with minimum friction. Megalodon infected over 5,500 GitHub repositories with malicious GitHub Actions workflows, while simultaneously, the TrapDoor campaign spread credential-stealing malware across npm, PyPI, and Crates.io with 34 malicious packages spanning 384 versions. These aren't coincidentally timed discoveries. They're evidence of a shift in attacker strategy — away from targeting individual applications and toward poisoning the tools developers rely on.

What makes Megalodon particularly insidious is its sophistication. The attack didn't create obviously malicious pull requests or commit messages that would raise red flags during code review. Instead, it injected fake automated commits containing GitHub Actions workflows designed to exfiltrate credentials, CI secrets, API keys, and tokens. From a developer's perspective scanning a GitHub feed, these look like routine automation commits — the kind that happen thousands of times a day in active repositories. The workflow runs with the repository's full permissions, meaning it has access to everything that CI/CD system can reach: production deployment secrets, third-party service credentials, internal API keys. An attacker who successfully extracts even one of these secrets from a major repository has essentially won the lottery.

The TrapDoor campaign operates at a different layer but with the same end goal: compromising developer credentials and secrets. By seeding malicious packages across the three largest open-source package ecosystems — npm, PyPI, and Crates.io — the attackers ensured that developers working in Python, JavaScript, and Rust would all be potentially exposed. The sophistication here is in the distribution strategy. Thirty-four packages across 384 versions creates a massive surface area. Some developers might pull a malicious version without realizing it, while others might eventually upgrade into one. The campaign had been running since May 22, which means it's only been public for a few days. We don't yet know how many projects are currently running malicious code.

Both campaigns target the same prize: credentials and secrets. But the distribution mechanisms are where these attacks show the evolution of supply chain thinking. Megalodon assumes developers trust GitHub and GitHub's commit history. It exploits that trust by hiding malicious code in plain sight as automation. TrapDoor assumes developers trust the package ecosystems and the packages they depend on. Neither assumption is unreasonable, which is precisely why these attacks work.

Against this backdrop, the Ghost CMS SQL injection vulnerability (CVE-2026-26980) being exploited in a large-scale ClickFix campaign deserves attention not because it's novel — SQL injection vulnerabilities and ClickFix attacks aren't new — but because it's simultaneously becoming a vector for injecting code into applications that depend on popular platforms. Ghost CMS powers countless blogs, news sites, and publishing platforms. A vulnerability here doesn't just affect the Ghost installation itself; it affects every reader who visits an infected site and becomes a potential victim of the ClickFix social engineering flows. The campaign is using JavaScript injection to redirect users to fake browser update pages or tech support scams. It's lower-sophistication than Megalodon or TrapDoor, but it's effective and it reaches a mass audience.

What connects all three attacks in our analysis is this: the entire stack is becoming a target. Developers thought the solution was to trust the big platforms — GitHub, npm, PyPI, CMS platforms. Those platforms are now the targets. The assumption that "official" repositories are safer because they're official is being systematically challenged. The infrastructure that developers built to reduce supply chain risk — centralized package repositories, automated deployment pipelines, content management platforms — has itself become the target.

The security implications cascade quickly. A developer running one compromised package from TrapDoor doesn't just expose their own environment — they potentially expose their entire organization's CI/CD credentials. An attacker who extracts a production deployment secret from a GitHub Actions exfiltration doesn't just have access to one repository; they may have keys to multiple environments. The blast radius isn't measured in installations anymore; it's measured in the credentials and secrets flowing through the development pipeline.

For security teams, the immediate takeaway is clear: you cannot trust that your dependencies are clean just because they came from an "official" repository. You need visibility into what packages you're pulling, what versions you're using, and what those packages are actually doing at runtime. You need to assume that GitHub Actions workflows in your repositories could be compromised. You need secret scanning that catches exfiltration attempts, not just accidental commits. And you need to understand that a vulnerability in a platform used by your developers — whether that's a CMS, a code hosting service, or a package registry — is effectively a vulnerability in your organization's security posture.

What we're watching develop is a fundamentally new threat model. The attacks are becoming smarter, more distributed, and more focused on the infrastructure rather than the application. We expect to see additional campaigns targeting other parts of the developer workflow in the coming weeks — container registries, CI/CD platforms, infrastructure-as-code repositories. The attackers have found the weak links in the supply chain, and they're exploiting them methodically.

Key Takeaways

  • Credential theft is now the primary objective of sophisticated supply chain attacks — both Megalodon and TrapDoor target secrets and keys that provide persistent access to infrastructure, not individual application vulnerabilities.
  • "Official" package repositories and platforms cannot be assumed secure — developers must implement secret scanning, dependency auditing, and runtime behavior monitoring regardless of where code originates.
  • The attack surface has expanded to include CI/CD pipelines and automation — malicious GitHub Actions workflows and package pre-install scripts now represent critical vectors that defenders must actively monitor.
  • Assume you're potentially affected if you use GitHub, npm, PyPI, Crates.io, or Ghost CMS — begin immediate audits of recent dependency updates, commits, and GitHub Actions workflows to detect compromise indicators.

The Wire is HackWire's daily editorial briefing, published every morning.