Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
AI Summary
Two compromised GitHub Actions, 'actions-cool/issues-helper' and 'actions-cool/maintain-one-comment', were reactivated on September 16, 2026, after being previously disabled due to their involvement in the Mini Shai-Hulud supply chain attack campaign. The repositories resumed serving malicious code that had been introduced on May 18, 2026, allowing credential harvesting from CI/CD pipelines without any new attacker action. The malicious payloads were re-downloaded and executed by workflows referencing the affected version tags, highlighting the risk of mutable version tags in supply chain security. The incident is linked to the Mini Shai-Hulud activity cluster, which also targeted npm packages under the @antv ecosystem.
AI-extracted · verify before operational use
Indicators of Compromise 4 extracted
| Type | Value | Detail |
|---|---|---|
| GitHub Repo | actions-cool/issues-helper | Details → |
| GitHub Repo | actions-cool/maintain-one-comment | Details → |
| Domain | t[.]m-kosche[.]com | Details → |
| Package | actions-cool/[email protected] | Details → |