Re-enabled GitHub Actions Again Ran Mini Shai-Hulud Stealer
Two GitHub Actions compromised in May were reachable again from September 16 to 25 with malicious tags that resumed stealing CI/CD secrets.
Socket reported that GitHub Actions actions-cool/issues-helper and actions-cool/maintain-one-comment, compromised on May 18, 2026, during the Mini Shai-Hulud campaign, became accessible again on September 16 with release tags still pointing at malicious content. Workflows referencing those tags downloaded and executed an obfuscated payload in index.js that harvested developer tokens, credentials, and CI/CD secrets; The Hacker News says the data was sent to an attacker-controlled server tied to t.m-kosche[.]com. BleepingComputer adds that the actions stayed live through September 25, that the May wave infected 323 npm packages and 639 versions, and that about 15,000 repositories depend on issues-helper, though not all pin mutable tags. The two reports agree on the reactivation and do not conflict; the later report supplies the end date and campaign scale. Workflows pinned to a full commit SHA from before May 18 were not affected. GitHub disabled both repositories again on September 25, and Socket advises removing the actions or pinning a clean commit, reviewing runs since September 16, and rotating exposed secrets.
- actions-cool/issues-helper and actions-cool/maintain-one-comment were compromised on May 18, 2026, in the Mini Shai-Hulud campaign.
- Both repositories were accessible again from September 16 to September 25, 2026, with release tags still resolving to the malicious commit.
- Workflows that referenced those tags resumed executing an obfuscated index.js payload that stole developer tokens, credentials, and CI/CD secrets.
- The Hacker News reported exfiltration to an attacker-controlled server tied to t.m-kosche[.]com.
- The May campaign infected 323 npm packages and 639 versions; GitHub lists about 15,000 repositories depending on issues-helper, not all of which pin mutable tags.
- Workflows pinned to a full commit SHA from before May 18 were not affected.
- GitHub disabled both actions again on September 25; Socket advises removing them or pinning a clean commit, reviewing runs since September 16, and rotating exposed secrets.
Coverage timelineoldest first · each row is one article
- · 1d agoCompromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
The Hacker News· 78
Re-enabled GitHub Actions again executed Mini Shai-Hulud payloads that stole CI/CD credentials.
- · 17h agoGitHub Actions re-enabled with Mini Shai-Hulud payload still active
BleepingComputer· 78
Two compromised GitHub Actions stayed live for nine days still serving the Mini Shai-Hulud payload.