importantSYS.SOURCE: The Hacker News• 2026-09-25T20:14:41+05:30
Reactivated Compromised GitHub Actions Resume Execution of Mini Shai-Hulud Malware
Compromised GitHub Actions were re-enabled, resuming execution of Mini Shai-Hulud malware that exfiltrates credentials from CI/CD pipelines. The malicious code remained in repositories after initial compromise, posing ongoing supply chain risks unless workflows are pinned to pre-compromise commit SHAs.
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign.
The affected GitHub Actions are listed below -
actions-cool/issues-helper actions-cool/maintain-one-comment
Visiting either of the repositories now shows the message: "Access to this
*** END OF TRANSMISSION ***