GitHub Actions re-enabled with Mini Shai-Hulud payload still active

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code.

After being compromised on May 18, the GitHub security team removed actions-cool/issues-helper and actions-cool/maintain-one-comment, preventing any downstream workflow from downloading malware.

According to researchers at application security company Socket, starting September 16 and up to September 25, the two actions became active again with the same release tags, causing workflows referencing their actions to download and execute the old payload.

The Mini Shai-Hulud supply-chain attack in May affected 323 packages and 639 package versions on the Node Package Manager (npm) index, infecting them with malware that targets developers’ tokens, credentials, and CI/CD secrets.

Socket researchers found that last Wednesday the release tags for actions-cool/issues-helper and actions-cool/maintain-one-comment resolved to a commit containing the obfuscated payload inside the ‘index.js’ file.

“On September 16, 2026, both repositories became accessible again. Their release tags were not cleaned up first," Socket explained.

"They still point to the malicious content introduced on May 18, so any workflow that references either action by a version tag resumed downloading and executing the payload on its next run.”

It is unclear exactly why these repositories were re-enabled without proper cleaning occurring first.

Incident timeline
Incident timelineSource: Socket

Socket says that GitHub’s dependency graph lists about 15,000 repositories depending on ‘issues-helper,’ though this does not mean all of them were compromised.

The researchers note that they have not yet established how many dependents reference either action by mutable tag instead of a pinned commit.

However, they explained that the impacted actions are those running almost daily, as they support issue-housekeeping needs.

On September 25, Socket found that both actions were disabled again on GitHub, leading workflows that reference them to fail instead of running the payload.

Socket recommends finding references to both actions, removing them or pinning a verified clean commit, reviewing runs since September 16, and rotating secrets accessible to workflows that ran an affected tag.

Potentially impacted developers should look for references to both actions and remove them or pin a verified clean commit.

The exposure started on September 16 between 11:09 and 18:16 GMT+2.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

进一步分析

免费工具,针对本文主题进一步深挖分析:

source: BleepingComputer