VMTech
Discuss a project →

Re-enabled GitHub Actions Reactivated Mini Shai-Hulud Malware

Re-enabled GitHub Actions Reactivated Mini Shai-Hulud Malware

Two compromised GitHub Actions from the actions-cool organization were disabled again after they became accessible on September 16, 2026, allowing malicious content from the May 18 Mini Shai-Hulud campaign to resume execution. The affected repositories are actions-cool/issues-helper and actions-cool/maintain-one-comment.

GitHub now displays a notice that access to each repository has been disabled by GitHub Staff for a violation of its terms of service. Socket researcher Karlo Zanki said the repositories were reachable again for part of September 16, between 11:09 a.m. and 6:16 p.m. GMT+2. The reason they were re-enabled is not known.

Old malicious tags became active again

The critical detail was not a newly published release or a changed workflow. Socket found that the actions’ release tags had not been cleaned up: they still resolved to malicious content introduced on May 18. Any workflow referring to either action through a version tag could therefore download and run the payload on its next execution.

The original compromise inserted code designed to harvest sensitive credentials from CI/CD pipelines and send them to an attacker-controlled server. The activity was tied to the Mini Shai-Hulud cluster through overlap with the t.m-kosche[.]com exfiltration domain, also seen in npm packages from the @antv ecosystem.

Both actions handle routine issue and comment maintenance, including closing inactive issues, checking new issues and maintaining a single bot comment. Workflows that call them commonly run daily or when an issue or pull request is opened. Socket said that, in practice, many affected repositories could have executed the payload within a day of the repositories becoming available again.

Mutable tags increase the supply-chain exposure

The episode illustrates how a dependency can become dangerous again even when an engineering team has not edited its own workflow configuration. No new malicious code had to be published, no account needed to be newly hijacked, and no new attacker infrastructure was required. Restoring repository availability was enough for workflows using mutable version tags to retrieve the already compromised action.

Workflows that pin an action to the full commit SHA of a version from before May 18, 2026, are not affected by this issue. A full SHA fixes the precise revision fetched by the workflow rather than relying on the state of an upstream tag.

Actions for development and security teams

Teams should locate every reference to the affected actions and treat actions-cool/issues-helper@v2.2.1 as affected. The actions should be removed or replaced with a known-clean commit SHA that predates May 18, 2026.

Organizations should also rotate secrets that may have been exposed, review workflow history for newly successful executions after a prolonged period of job failures, and audit repository history for unexpected commits after September 16. The practical implication is that CI/CD dependency inventories and SHA pinning must be paired with incident review, because a mutable upstream tag can reactivate a contained compromise without a local workflow change.

#githubactions#supplychain#cicdsecurity#malware
Open analytics
On the site 3 views
min read 3 25.09.2026
On Instagram 4 views
On Instagram 1 reach
Instagram

Re-enabled GitHub Actions Reactivated Mini Shai-Hulud Malware

Open the post on Instagram ↗