Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets (opens in new tab)
codfish/semantic-release-action was compromised on June 24, 2026. Attackers repointed v2–v5 tags to a Miasma credential-stealing payload targeting CI/CD secrets. Here's what happened and how to check if you're affected. Category: Vulnerabilities & Threats
Read the original article