Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Re-enabled GitHub Actions again executed Mini Shai-Hulud payloads that stole CI/CD credentials.
Socket reports that actions-cool/issues-helper and actions-cool/maintain-one-comment, compromised on May 18, 2026 in the Mini Shai-Hulud campaign, became accessible again on September 16. Their release tags still pointed at malicious content, so workflows referencing those tags resumed downloading a payload that harvested CI/CD credentials and exfiltrated them to an attacker-controlled server tied to t.m-kosche[.]com. GitHub Staff has disabled both repositories again. Workflows pinned to a full commit SHA from before May 18 were not affected; Socket advises removing the actions, rotating secrets, and reviewing runs after September 16.