On June 24, 2026, the simonecorsi/mawesome GitHub Action repository was compromised via a force-push attack that repointed version tags to malicious commits. Any workflow using those tags executed attacker-controlled code inside GitHub Actions runners. The attack method mirrors a similar compromise of codfish/semantic-release-action reported the same day.

1m read timeFrom stepsecurity.io
Post cover image
Table of contents
Acknowledgement
4.2K Impressions