Two GitHub Actions from the actions-cool project were disabled again after becoming accessible and reactivating malicious payloads tied to the May 2026 Mini Shai-Hulud campaign. The incident highlights how mutable version tags can silently reintroduce supply chain risk, and why SHA pinning is critical for protection. #actions-cool #MiniShaiHulud #GitHubActions
Keypoints
- Two actions-cool GitHub Actions were disabled again after being re-enabled.
- The repositories still contained malicious code from the May 18, 2026 compromise.
- Version tags pointed to the malicious content and restarted payload delivery.
- The activity was linked to the Mini Shai-Hulud cluster through shared infrastructure.
- Developers should remove the actions, pin to a clean SHA, rotate secrets, and review workflow history.
Read More: https://thehackernews.com/2026/09/compromised-github-actions-came-back.html