socket-dev · Crawled Sep 25, 2026

Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud

4 IoCs
Read original article ↗

AI Summary

The compromised GitHub Actions repositories 'actions-cool/issues-helper' and 'actions-cool/maintain-one-comment' were re-enabled on September 16, 2026, while still hosting malicious code from the May 2026 Mini Shai-Hulud campaign. This reactivation allowed the malicious payload to execute in downstream workflows that referenced the actions by mutable tags, affecting an estimated 15,000+ repositories. The attack resumed without any new exploit or infrastructure, as the malicious tags were never cleaned. Workflows referencing these actions by tag instead of pinned commit SHA began executing the obfuscated payload, which installs the Bun runtime and runs a malicious script, potentially exfiltrating secrets and gaining unauthorized access.

AI-extracted · verify before operational use

Indicators of Compromise 4 extracted

Type Value Detail
GitHub Repo actions-cool/issues-helper Details →
GitHub Repo actions-cool/maintain-one-comment Details →
Package oven-sh/setup-bun Details →
GitHub User oven-sh Details →