GitHub Actions re-enabled with Mini Shai-Hulud malware still active

Two GitHub Actions (issues-helper and maintain-one-comment) previously compromised in the May 2026 Mini Shai-Hulud campaign were re-enabled on September 16, 2026, with malicious tags still intact. The actions remained accessible for over a week, executing malware in dependent workflows before GitHub disabled them again.

1 report · +5 socialother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

🚨 Two GitHub Actions compromised in May’s Mini Shai-Hulud campaign are running malware again. The repositories were re-enabled with malicious release tags intact, putting thousands of downstream repo

mastodon:fosstodonother5d ago kagi ↗

🚨 Two GitHub Actions compromised in May’s Mini Shai-Hulud campaign are running malware again. The repositories were re-enabled with malicious release tags intact, putting thousands of downstream repositories at risk. https:// socket.dev/blog/mini-shai-hulu d-actions

Two actions-cool GitHub Actions compromised in the May Mini Shai-Hulud campaign became accessible again on Sept 16 with tainted tags still intact, before GitHub re-disabled them. It shows restored rep

mastodon:infosec-exchangeother4d ago kagi ↗

Two actions-cool GitHub Actions compromised in the May Mini Shai-Hulud campaign became accessible again on Sept 16 with tainted tags still intact, before GitHub re-disabled them. It shows restored repos can silently revive known supply-chain payloads if tags are not purged. # SupplyChain # GitHubActions # ShaiHulud https:// cyberworldops.eu/en/restored-g ithub-actions-repositories-briefly-revived-

⚠️ CRITICAL: Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud Two GitHub Actions (issues-helper and maintain-one-comment) were re-enabled on September 16, 2026 with malici

mastodon:infosec-exchangeother3d ago kagi ↗

⚠️ CRITICAL: Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud Two GitHub Actions (issues-helper and maintain-one-comment) were re-enabled on September 16, 2026 with malicious code still present, resuming execution across approximately 15,000 dependent repositories. Any workflow referencing these actions by tag is now executing the Mini Shai-Hulud malware payl… https://

🤖 Two GitHub Actions compromised in the May 2026 Mini Shai-Hulud campaign were re-enabled on Sept 16 and immediately resumed executing the malicious payload in workflows that referenced them by versi

mastodon:infosec-exchangeother3d ago kagi ↗

🤖 Two GitHub Actions compromised in the May 2026 Mini Shai-Hulud campaign were re-enabled on Sept 16 and immediately resumed executing the malicious payload in workflows that referenced them by version tag. Their release tags still pointed to the May 18 malicious commit. GitHub disabled both repos again. 🔗 https:// thehackernews.com/2026/09/comp romised-github-actions-came-back.html # SupplyChai

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious

mastodon:infosec-exchangeother3d ago kagi ↗

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. https://www. bleepingcomputer.com/news/secu rity/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/