Last Updated: 2026-06-24T18:43:16Z
What’s Happening
Step Security reported that the codfish/semantic-release GitHub Action had been compromised with a malicious bun run command and index.js. At the time of their reporting, they were unable to determine the nature of the malware. Our initial analysis suggests this is a modified version of Mini Shai-Hulud.
The novel functionality is installing persistence to multiple AI assistant/IDE config folders, so the malware will run on startup of these tools.
Actions
As always, check your supply chain for the presence of this GitHub action. As this is an infostealer/worm, rotate all credentials adjacent to affected systems/identities.
Notes
Seriously, if you’re not a JS dev shop, maybe block Bun?