← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Compromised GitHub Actions Re-enabled, Resuming Mini Shai-Hulud Malware Execution

🔄 Updated 5h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Two GitHub Actions repositories were re-enabled on September 16, 2026.
  • Malicious code from the May 2026 Mini Shai-Hulud campaign remained.
  • Workflows using these actions resumed executing the malware.
  • The re-enabling created a software supply chain security risk.

Compromised Actions Re-enabled

Two GitHub Actions repositories, previously disabled due to compromise, were re-enabled on September 16, 2026. These actions had been involved in the Mini Shai-Hulud campaign in May 2026, which targeted CI/CD pipelines to harvest credentials.

Malicious Content Persisted

Upon re-enabling, the repositories still contained the malicious content introduced on May 18, 2026. Socket researcher Karlo Zanki noted that the release tags were not cleaned up, meaning any workflow referencing these actions by a version tag would resume downloading and executing the payload.

Mini Shai-Hulud Campaign Link

The original compromise was linked to the Mini Shai-Hulud activity cluster due to overlaps in the exfiltration domain used in the GitHub Actions workflows and certain npm packages. This indicates a continued threat from the same actor group.

Supply Chain Risk

The re-activation of these compromised actions without remediation presented a significant software supply chain security risk. Existing workflows that utilize these actions would automatically execute the malicious code, potentially leading to credential exfiltration without requiring new exploits or infrastructure from the attackers.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~17 min · 13 stories · Sep 25

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Two GitHub Actions repositories, previously compromised in May 2026 by the Mini Shai-Hulud campaign, were re-enabled on September 16, 2026, without the malicious code being removed. This allowed workflows referencing these actions to resume downloading and executing the malware, posing a software supply chain risk.