Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets
aikido.dev | blog | #supply-chain | #devsecops | #secrets | #github-actions | #npm | #ci-cd | #supply-chain-attack | #supply-chain-security | #secrets-theft | #tag-hijacking | #semantic-release | #imposter-commits | #imposter-commit
Summary
codfish/semantic-release-action was hit by an imposter commit attack: force-pushed commits repointed 16 tags including v2-v5, so workflows pinning them run attacker code with CI/CD secrets access.
- Published
- Collected
Skip to content