Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
AI Summary
The compromised GitHub Actions repositories 'actions-cool/issues-helper' and 'actions-cool/maintain-one-comment' were re-enabled on September 16, 2026, while still hosting malicious code from the May 2026 Mini Shai-Hulud campaign. This reactivation allowed the malicious payload to execute in downstream workflows that referenced the actions by mutable tags, affecting an estimated 15,000+ repositories. The attack resumed without any new exploit or infrastructure, as the malicious tags were never cleaned. Workflows referencing these actions by tag instead of pinned commit SHA began executing the obfuscated payload, which installs the Bun runtime and runs a malicious script, potentially exfiltrating secrets and gaining unauthorized access.
AI-extracted · verify before operational use