GitHub Actions Re-enabled: Mini Shai-Hulud Payload Remains Active
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Reactivation of Compromised GitHub Actions
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. The actions-cool/issues-helper and actions-cool/maintain-one-comment were initially compromised on May 18, leading the GitHub security team to remove them. Researchers at application security firm Socket discovered that starting September 16 and continuing through September 25, the two actions became active again with the same release tags, causing workflows referencing their actions to execute the malicious payload.
Details of the Mini Shai-Hulud Attack
The Mini Shai-Hulud supply-chain attack in May impacted 323 packages and 639 package versions on the Node Package Manager (npm) index, infecting them with malware designed to steal developers’ tokens, credentials, and CI/CD secrets.
The repositories were reactivated without cleaning the malicious content, allowing workflows that referenced the actions via version tags to resume execution of the compromised code. The exact reason for the re-enablement without remediation remains unclear.
Socket’s Observations and Recommendations
On September 25, Socket observed that both actions were disabled again on GitHub, causing workflows referencing them to fail rather than execute the payload.
The exposure window began on September 16 between 11:09 and 18:16 GMT+2.
