bleeping-computer · Crawled Sep 26, 2026
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
2 IoCs
Read original article ↗
AI Summary
Two previously compromised GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were re-enabled by their maintainer on September 16, 2026, without removing the malicious payload from May's Mini Shai-Hulud supply-chain attack. The actions continued to serve an obfuscated malicious payload in 'index.js', causing dependent workflows to execute malware that targets developer tokens, credentials, and CI/CD secrets. The repositories were re-disabled on September 25 after researchers at Socket raised the alarm. Developers are advised to remove or pin these actions and rotate potentially exposed secrets.
AI-extracted · verify before operational use