Two GitHub Actions repositories, previously disabled due to compromise, were re-enabled on September 16, 2026. These actions had been involved in the Mini Shai-Hulud campaign in May 2026, which targeted CI/CD pipelines to harvest credentials.
Upon re-enabling, the repositories still contained the malicious content introduced on May 18, 2026. Socket researcher Karlo Zanki noted that the release tags were not cleaned up, meaning any workflow referencing these actions by a version tag would resume downloading and executing the payload.
The original compromise was linked to the Mini Shai-Hulud activity cluster due to overlaps in the exfiltration domain used in the GitHub Actions workflows and certain npm packages. This indicates a continued threat from the same actor group.
The re-activation of these compromised actions without remediation presented a significant software supply chain security risk. Existing workflows that utilize these actions would automatically execute the malicious code, potentially leading to credential exfiltration without requiring new exploits or infrastructure from the attackers.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Two GitHub Actions repositories, previously compromised in May 2026 by the Mini Shai-Hulud campaign, were re-enabled on September 16, 2026, without the malicious code being removed. This allowed workflows referencing these actions to resume downloading and executing the malware, posing a software supply chain risk.