simonecorsi/mawesome GitHub Action Tag Hijack

Confirmed
Discovered Jun 25, 2026

Mutable refs for simonecorsi/mawesome including latest, v1, v2, and v2.2.0 currently resolve to a composite action that installs Bun and always runs an obfuscated JavaScript payload, exposing GitHub Actions runners that still trust those tags.

4
Affected Packages
15
Observables
5
Sources

Timeline

1 of 1 rows

Timeline
DateEventDescriptionSource
Jun 25, 2026Fresh source reviewReviewed direct and primary sources for the last-two-weeks supply-chain refresh; this preview intentionally excludes older Halting Problems article data.Direct source

Affected Software

4 of 4 rows

Affected Software
PackageEcosystemVersion RangeStatusConfidenceSource
simonecorsi/mawesomeGitHublatestMalicious90%Direct source
simonecorsi/mawesomeGitHubv1Malicious90%Direct source
simonecorsi/mawesomeGitHubv2Malicious90%Direct source
simonecorsi/mawesomeGitHubv2.2.0Malicious90%Direct source

IOC Clipboard

15 IOCs
urlhttps://raw.githubusercontent.com/simonecorsi/mawesome/v1/action.yml
urlhttps://raw.githubusercontent.com/simonecorsi/mawesome/main/action.yml
urlhttps://raw.githubusercontent.com/simonecorsi/mawesome/v1/index.js
hashe339407b8e34dc1540290d1d310bccafbc6028ca
hash4a665037e0619e2181c7cccc3291d75104175a92
hash6e26314c306ed5ea744eb90ebc6f3f70298abcb5
hash7a59a7d02b1fdf6432ea9467b8e31357217288f7
file_pathaction.yml
file_pathindex.js
commandoven-sh/setup-bun
commandbun run $GITHUB_ACTION_PATH/index.js
commandcreateCipheriv
commandcreateDecipheriv
commandpbkdf2Sync
commandVAULT_TOKEN

Provenance & Sources

5 of 5 rows

Provenance & Sources
SourceTypeReliabilityClaimsEvidence
Direct sourcedirect95%1https://api.github.com/repos/simonecorsi/mawesome/tags?per_page=100
Direct sourcedirect95%1https://api.github.com/repos/simonecorsi/mawesome/commits/e339407b8e34dc1540290d1d310bccafbc6028ca
Direct sourcedirect95%1https://raw.githubusercontent.com/simonecorsi/mawesome/v1/action.yml
Direct sourcedirect95%1https://raw.githubusercontent.com/simonecorsi/mawesome/main/action.yml
Primary researchprimary research95%1https://www.stepsecurity.io/blog/simonecorsi-mawesome-github-action-has-been-compromised