← All stories
● Covered by 2 sources · 2 reportsMedium impact2 negative

Compromised GitHub Actions Re-enabled, Resuming Mini Shai-Hulud Malware Execution

🔄 Updated 6d ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Two GitHub Actions repositories were re-enabled on September 16, 2026.
  • Malicious code from the May 2026 Mini Shai-Hulud campaign remained.
  • Workflows using these actions resumed executing the malware.
  • The re-enabling created a software supply chain security risk.
  • The re-enabled repositories were 'actions-cool/issues-helper' and 'actions-cool/maintain-one-comment'.
  • The actions were re-enabled by their maintainer.
  • The actions remained accessible for over a week, until September 25.
  • The malware could expose developer tokens, credentials, and CI/CD secrets.
  • The Mini Shai-Hulud attack in May affected 323 packages and 639 package versions on npm.
  • The malicious code was found in the 'index.js' file.

Compromised Actions Re-enabled

Two GitHub Actions repositories, previously disabled due to compromise, were re-enabled on September 16, 2026. These actions had been involved in the Mini Shai-Hulud campaign in May 2026, which targeted CI/CD pipelines to harvest credentials.

Malicious Content Persisted

Upon re-enabling, the repositories still contained the malicious content introduced on May 18, 2026. Socket researcher Karlo Zanki noted that the release tags were not cleaned up, meaning any workflow referencing these actions by a version tag would resume downloading and executing the payload.

Mini Shai-Hulud Campaign Link

The original compromise was linked to the Mini Shai-Hulud activity cluster due to overlaps in the exfiltration domain used in the GitHub Actions workflows and certain npm packages. This indicates a continued threat from the same actor group.

Supply Chain Risk

The re-activation of these compromised actions without remediation presented a significant software supply chain security risk. Existing workflows that utilize these actions would automatically execute the malicious code, potentially leading to credential exfiltration without requiring new exploits or infrastructure from the attackers.

Updates

🕒 2026-09-26 · new reporting from BleepingComputer
  • The re-enabled repositories were 'actions-cool/issues-helper' and 'actions-cool/maintain-one-comment'.
  • The actions were re-enabled by their maintainer.
  • The actions remained accessible for over a week, until September 25.
  • The malware could expose developer tokens, credentials, and CI/CD secrets.
  • The Mini Shai-Hulud attack in May affected 323 packages and 639 package versions on npm.
  • The malicious code was found in the 'index.js' file.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Two GitHub Actions previously compromised in the Mini Shai-Hulud campaign were re-enabled by their maintainer from September 16 to September 25, still pointing to malicious code. This allowed workflows referencing these actions to download and execute the malware again, potentially exposing developer tokens, credentials, and CI/CD secrets.

Two GitHub Actions repositories, previously compromised in May 2026 by the Mini Shai-Hulud campaign, were re-enabled on September 16, 2026, without the malicious code being removed. This allowed workflows referencing these actions to resume downloading and executing the malware, posing a software supply chain risk.