socket.dev Re-enabled Malicious GitHub Actions Expose Thousands to Mini Shai-Hulud Payload
Article Content
- •Two compromised GitHub Actions were re-enabled, exposing thousands of repositories.
- •The malicious code remained intact, allowing workflows to execute the payload again.
- •Developers are urged to pin actions to known-clean SHAs and rotate exposed secrets.
On September 16, 2026, two compromised GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-, were re-enabled, exposing thousands of downstream repositories to malicious code from the May 2026 Mini Shai-Hulud campaign. The malicious tags remained intact, allowing workflows referencing these actions by version tag to resume executing the payload. The GitHub Actions were initially disabled on May 19, 2026, after being compromised on May 18, 2026, to harvest sensitive credentials from CI/CD pipelines. The threat actor did not need new exploits or infrastructure; the malicious code was already present. GitHub's dependency graph lists around 15,000 dependent repositories for actions-cool/issues-helper alone. Developers are advised to remove the affected actions, pin them to known-clean SHAs, and rotate exposed secrets. The current status is that both actions have been disabled again as of September 25, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Mini Shai-Hulud in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
UAC-0099 Uses GuardBreaker to Evade AI Malware Detection Russian-linked hackers from the group UAC-0099 have developed a new technique called GuardBreaker to evade AI-assisted malware analysis. This method involves embedding a nuclear weapon prompt in malicious VBS scripts, which distracts AI systems from analyzing the actual malware code. The script is designed to download…
Critical OVERPASS Vulnerability in SAP Kernel Requires Immediate Action On September 8, 2026, SAP released security updates addressing 20 vulnerabilities, including a critical memory corruption flaw tracked as CVE-2026-44756, named OVERPASS. This vulnerability allows unauthenticated attackers to execute arbitrary commands on vulnerable SAP systems, leading to full compromise of business…