Compromised GitHub Actions reactivated with May's Shai-Hulud malware still intact
GitHub Actions repositories actions-cool/issues-helper and actions-cool/maintain-one-comment, disabled in May after being compromised in the Mini Shai-Hulud supply-chain attack, were reinstated by their maintainer starting September 16 without removing the malicious code. Socket researchers found the release tags still pointed to the original tainted commit, meaning any workflow referencing those version tags resumed downloading and executing the malware payload through at least September 25.
GoKawiil's interpretation of the reporting above, not reported fact.
Roughly 15,000 repositories reportedly depend on issues-helper via GitHub's dependency graph, though Socket says it is unclear how many actually reference the compromised version tags rather than pinned commits, so the real exposure remains uncertain. The episode suggests that disabling a compromised repository is not enough if it can later be reactivated without a security review, raising questions about how GitHub and maintainers handle cleanup after supply-chain incidents.
- Two GitHub Actions compromised in May's Mini Shai-Hulud campaign were reactivated in September still carrying the malicious payload.
- About 15,000 repositories reportedly depend on one of the affected actions, though actual compromise numbers are unconfirmed.
- Workflows referencing the actions by mutable version tags, rather than pinned commits, were vulnerable to re-execution of the malware.
Source: bleepingcomputer.com, 2026-09-26
Published there as: “GitHub Actions re-enabled with Mini Shai-Hulud payload still active”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.