Skip to content
Tech News
← Back to articles

Compromised GitHub Actions reactivated with May's Shai-Hulud malware still intact

read original more articles
GoKawiil Brief

GitHub Actions repositories actions-cool/issues-helper and actions-cool/maintain-one-comment, disabled in May after being compromised in the Mini Shai-Hulud supply-chain attack, were reinstated by their maintainer starting September 16 without removing the malicious code. Socket researchers found the release tags still pointed to the original tainted commit, meaning any workflow referencing those version tags resumed downloading and executing the malware payload through at least September 25.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

Roughly 15,000 repositories reportedly depend on issues-helper via GitHub's dependency graph, though Socket says it is unclear how many actually reference the compromised version tags rather than pinned commits, so the real exposure remains uncertain. The episode suggests that disabling a compromised repository is not enough if it can later be reactivated without a security review, raising questions about how GitHub and maintainers handle cleanup after supply-chain incidents.

Key Takeaways

Source: bleepingcomputer.com, 2026-09-26

Published there as: “GitHub Actions re-enabled with Mini Shai-Hulud payload still active”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.