Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets
ID: 3e11a972-73b6-5a4e-a242-c874609ac7f7
STIX ID: report--3e11a972-73b6-5a4e-a242-c874609ac7f7
Feed Name: Aikido Security's Blog
On 2026-06-24 the codfish/semantic-release-action GitHub Action was hijacked via an imposter commit attack: the attacker force-pushed two orphan commits and repointed sixteen tags (including major floating tags v2–v5) so workflows referencing those tags would execute an obfuscated index.js payload. The payload contains a marker linking it to the Miasma credential-stealing toolkit (which uses GitHub commit search as a dead-drop), enabling token/credential theft from runners that expose GITHUB_TOKEN/NPM_TOKEN; the report provides payload hashes, affected/clean tags, and indicators for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
