5,561 repos backdoored in 6 hours.
No zero-day. No leaked password. Just GitHub Actions workflows that trusted too much.
That was the Megalodon campaign in May. Before it came tj-actions, Trivy, Checkmarx and Bitwarden CLI. The playbook was the same each time: get into CI, steal the secrets, walk into prod.
The uncomfortable part: your pipeline probably has more access than any engineer on your team. AWS keys, registry tokens, deploy rights. Almost nobody reviews it like prod.
Run this 60-second check on your repo
1. Workflows triggered by pull_request_target
grep -rn "pull_request_target" .github/workflows
Any hit → make sure it never runs PR code with secrets in scope.
2. Actions pinned to a tag
grep -rnE "uses: .+@v[0-9]" .github/workflows
Any hit → you're trusting a tag someone can move. Pin to a commit SHA.
3. Long-lived cloud keys
grep -rn "AWS_SECRET_ACCESS_KEY" .github/workflows
Any hit → long-lived keys waiting to be stolen. Switch to OIDC.
4. Default token permissions
grep -L "permissions:" .github/workflows/*.yml
Any file listed → default token permissions. Set them explicitly, read-only first.
All four clean? You're ahead of most teams. Not clean? You just found this sprint's most important ticket.
How many hits did you get?