GitHub Actions Re-enabled: Mini Shai-Hulud Payload Remains Active

www.news4hackers.com-github-actions-re-enabled-mini-shai-hulud-payload-remains-active-github-actions-re-enabled-mini-shai-hulud-payload-remains-active

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Reactivation of Compromised GitHub Actions

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. The actions-cool/issues-helper and actions-cool/maintain-one-comment were initially compromised on May 18, leading the GitHub security team to remove them. Researchers at application security firm Socket discovered that starting September 16 and continuing through September 25, the two actions became active again with the same release tags, causing workflows referencing their actions to execute the malicious payload.

Details of the Mini Shai-Hulud Attack

The Mini Shai-Hulud supply-chain attack in May impacted 323 packages and 639 package versions on the Node Package Manager (npm) index, infecting them with malware designed to steal developers’ tokens, credentials, and CI/CD secrets.

Socket researchers identified that on September 16, 2026, the release tags for actions-cool/issues-helper and actions-cool/maintain-one-comment resolved to a commit containing an obfuscated payload within the index.js file.

The repositories were reactivated without cleaning the malicious content, allowing workflows that referenced the actions via version tags to resume execution of the compromised code. The exact reason for the re-enablement without remediation remains unclear.

Socket’s Observations and Recommendations

Socket noted that the GitHub dependency graph lists approximately 15,000 repositories relying on issues-helper, though not all may have been affected. The firm highlighted uncertainty about how many dependents used mutable tags instead of pinned commits, but emphasized that the impacted actions are frequently utilized for daily issue-housekeeping tasks.

On September 25, Socket observed that both actions were disabled again on GitHub, causing workflows referencing them to fail rather than execute the payload.

The firm advised users to identify and remove references to the compromised actions, pin verified clean commits, review workflows executed since September 16, and rotate secrets accessible to affected workflows. Developers potentially exposed should inspect their repositories for the actions and take corrective measures.

The exposure window began on September 16 between 11:09 and 18:16 GMT+2.

Conclusion and Ongoing Risks

Researchers stressed the urgency of mitigating dependencies on the compromised actions to prevent further exploitation. The incident underscores ongoing risks in supply-chain ecosystems and the importance of verifying third-party components before integration.



About Author

en_USEnglish