bleeping-computer · Crawled Sep 26, 2026

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

2 IoCs
Read original article ↗

AI Summary

Two previously compromised GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were re-enabled by their maintainer on September 16, 2026, without removing the malicious payload from May's Mini Shai-Hulud supply-chain attack. The actions continued to serve an obfuscated malicious payload in 'index.js', causing dependent workflows to execute malware that targets developer tokens, credentials, and CI/CD secrets. The repositories were re-disabled on September 25 after researchers at Socket raised the alarm. Developers are advised to remove or pin these actions and rotate potentially exposed secrets.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
GitHub Repo actions-cool/issues-helper Details →
GitHub Repo actions-cool/maintain-one-comment Details →