Skip to content

Trusted Dev Tools Abused to Steal Code and Secrets

Gbhackers Mayura Kathir May 29, 2026

Attackers are increasingly weaponizing trusted developer tools to infiltrate software supply chains, with CISA warning of multiple ongoing campaigns targeting CI/CD ecosystems and developer workflows. Recent incidents, including a compromised Visual Studio Code extension and a large-scale operation dubbed “Megalodon,” highlight how adversaries are exploiting the very tools designed to accelerate modern software development. One […]

Extracted Entities

Attack Types (1)

Campaigns (1)

Platforms (1)