Mini Shai-Hulud hits codfish/semantic-release

Last Updated: 2026-06-24T18:43:16Z

What’s Happening

Step Security reported that the codfish/semantic-release GitHub Action had been compromised with a malicious bun run command and index.js. At the time of their reporting, they were unable to determine the nature of the malware. Our initial analysis suggests this is a modified version of Mini Shai-Hulud.

The novel functionality is installing persistence to multiple AI assistant/IDE config folders, so the malware will run on startup of these tools.

Actions

As always, check your supply chain for the presence of this GitHub action. As this is an infostealer/worm, rotate all credentials adjacent to affected systems/identities.

Notes

Seriously, if you’re not a JS dev shop, maybe block Bun?