hacker-news · Crawled Sep 25, 2026

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

4 IoCs
Read original article ↗

AI Summary

Two compromised GitHub Actions, 'actions-cool/issues-helper' and 'actions-cool/maintain-one-comment', were reactivated on September 16, 2026, after being previously disabled due to their involvement in the Mini Shai-Hulud supply chain attack campaign. The repositories resumed serving malicious code that had been introduced on May 18, 2026, allowing credential harvesting from CI/CD pipelines without any new attacker action. The malicious payloads were re-downloaded and executed by workflows referencing the affected version tags, highlighting the risk of mutable version tags in supply chain security. The incident is linked to the Mini Shai-Hulud activity cluster, which also targeted npm packages under the @antv ecosystem.

AI-extracted · verify before operational use

Indicators of Compromise 4 extracted

Type Value Detail
GitHub Repo actions-cool/issues-helper Details →
GitHub Repo actions-cool/maintain-one-comment Details →
Domain t[.]m-kosche[.]com Details →
Package actions-cool/[email protected] Details →