Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Two GitHub Actions Re-enabled With Mini Shai-Hulud Payload

Two third-party GitHub Actions linked to the Mini Shai-Hulud campaign were re-enabled with malicious code still in their release tags, according to application security company Socket. The actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were accessible again from September 16 through September 25, 2026.

GitHub’s security team had removed the actions after they were compromised on May 18, preventing downstream workflows from downloading the payload. Socket said the repositories became accessible again on September 16, but their release tags still pointed to a commit containing obfuscated code in the index.js file. Workflows using either action by version tag could therefore download and execute the payload on their next run.

The May Mini Shai-Hulud supply-chain attack affected 323 packages and 639 package versions on npm, targeting developers’ tokens, credentials, and CI/CD secrets. Socket said GitHub’s dependency graph lists about 15,000 repositories depending on issues-helper, but that figure does not mean all were compromised. Researchers had not established how many dependents used mutable tags rather than pinned commits.

Socket found both actions disabled again on September 25, causing referencing workflows to fail instead of running the payload. The company recommends checking for references to both actions, removing them or pinning a verified clean commit, reviewing runs since September 16, and rotating secrets accessible to workflows that ran an affected tag.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.