logo

Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets

ID: 3e11a972-73b6-5a4e-a242-c874609ac7f7

STIX ID: report--3e11a972-73b6-5a4e-a242-c874609ac7f7

Feed Name: Aikido Security's Blog

Threat Score
78/100

Date Published: 2026-06-24

Date Updated: 2026-07-24

...
...

On 2026-06-24 the codfish/semantic-release-action GitHub Action was hijacked via an imposter commit attack: the attacker force-pushed two orphan commits and repointed sixteen tags (including major floating tags v2–v5) so workflows referencing those tags would execute an obfuscated index.js payload. The payload contains a marker linking it to the Miasma credential-stealing toolkit (which uses GitHub commit search as a dead-drop), enabling token/credential theft from runners that expose GITHUB_TOKEN/NPM_TOKEN; the report provides payload hashes, affected/clean tags, and indicators for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.