codfish/semantic-release-action GitHub Action Tag Hijack
ConfirmedDiscovered Jun 24, 2026
An attacker force-pushed a malicious composite action into codfish/semantic-release-action and moved fifteen published tags to that commit, exposing GitHub Actions runners that still trusted mutable refs such as v3, v4, and v5.
10
Affected Packages
9
Observables
5
Sources
Timeline
| Date | Event | Description | Source |
|---|---|---|---|
| Jun 24, 2026 | Fresh source review | Reviewed direct and primary sources for the last-two-weeks supply-chain refresh; this preview intentionally excludes older Halting Problems article data. | Direct source |
Affected Software
| Package | Ecosystem | Version Range | Status | Confidence | Source |
|---|---|---|---|---|---|
| codfish/semantic-release-action | GitHub | v5.0.0 | Malicious | 90% | Direct source |
| codfish/semantic-release-action | GitHub | v5 | Malicious | 90% | Direct source |
| codfish/semantic-release-action | GitHub | v4.0.1 | Malicious | 90% | Direct source |
| codfish/semantic-release-action | GitHub | v4.0.0 | Malicious | 90% | Direct source |
| codfish/semantic-release-action | GitHub | v4 | Malicious | 90% | Direct source |
| codfish/semantic-release-action | GitHub | v3.5.0 | Malicious | 90% | Direct source |
| codfish/semantic-release-action | GitHub | v3.4.1 | Malicious | 90% | Direct source |
| codfish/semantic-release-action | GitHub | v3.4.0 | Malicious | 90% | Direct source |
| codfish/semantic-release-action | GitHub | v3.3.0 | Malicious | 90% | Direct source |
| codfish/semantic-release-action | GitHub | v3.2.0 | Malicious | 90% | Direct source |
IOC Clipboard
9 IOCsurl
https://raw.githubusercontent.com/codfish/semantic-release-action/5792aba0e2180b9b80b77644370a6889d5817456/action.ymlurl
https://raw.githubusercontent.com/codfish/semantic-release-action/8f9a58f2acdc190c356f79159b5de2548cdb63cd/action.ymlhash
5792aba0e2180b9b80b77644370a6889d5817456hash
8f9a58f2acdc190c356f79159b5de2548cdb63cdfile_path
action.ymlfile_path
index.jscommand
oven-sh/setup-buncommand
bun run $GITHUB_ACTION_PATH/index.jscommand
Runner.Worker memory accessProvenance & Sources
| Source | Type | Reliability | Claims | Evidence |
|---|---|---|---|---|
| Direct source | direct | 95% | 1 | https://api.github.com/repos/codfish/semantic-release-action |
| Direct source | direct | 95% | 1 | https://api.github.com/repos/codfish/semantic-release-action/tags?per_page=100 |
| Direct source | direct | 95% | 1 | https://raw.githubusercontent.com/codfish/semantic-release-action/5792aba0e2180b9b80b77644370a6889d5817456/action.yml |
| Direct source | direct | 95% | 1 | https://raw.githubusercontent.com/codfish/semantic-release-action/8f9a58f2acdc190c356f79159b5de2548cdb63cd/action.yml |
| Primary research | primary research | 95% | 1 | https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action |