---
title: "simonecorsi/mawesome GitHub Action has been compromised"
url: https://daily.dev/posts/simonecorsi-mawesome-github-action-has-been-compromised-ckc9svqze
source_url: https://www.stepsecurity.io/blog/simonecorsi-mawesome-github-action-has-been-compromised
type: article
source: "StepSecurity"
published: 2026-06-25T01:41:34.515Z
updated: 2026-06-25T01:41:49.643Z
tags: ["security", "cyber", "cicd", "github-actions"]
reading_time: 1
upvotes: 1
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# simonecorsi/mawesome GitHub Action has been compromised

**[StepSecurity](https://daily.dev/sources/stepsecurity)** · 1 min read · 1 upvotes · 0 comments

## Summary

On June 24, 2026, the simonecorsi/mawesome GitHub Action repository was compromised via a force-push attack that repointed version tags to malicious commits. Any workflow using those tags executed attacker-controlled code inside GitHub Actions runners. The attack method mirrors a similar compromise of codfish/semantic-release-action reported the same day.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.stepsecurity.io/blog/simonecorsi-mawesome-github-action-has-been-compromised>

## Similar posts on daily.dev

- [actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Commit That Exfiltrates CI/CD Credentials](https://daily.dev/posts/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltr-12ij52s4u) · StepSecurity · 2 upvotes · 0 comments
- [Supply Chain Compromise: codfish/semantic-release-action Tags Hijacked to Steal OIDC Tokens and Propagate Backdoors](https://daily.dev/posts/supply-chain-compromise-codfish-semantic-release-action-tags-hijacked-to-steal-oidc-tokens-and-prop-y1h87nkdy) · StepSecurity · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#cicd](https://daily.dev/tags/cicd), [#github-actions](https://daily.dev/tags/github-actions)

[View this post on daily.dev](https://daily.dev/posts/simonecorsi-mawesome-github-action-has-been-compromised-ckc9svqze)
