GitHub Actions re-enabled with Mini Shai-Hulud payload still active

GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Two GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were re-enabled after a Mini Shai-Hulud compromise and continued serving malicious code for more than a week. The exposure could have affected workflows that referenced the actions by mutable tags, putting developer tokens, credentials, and CI/CD secrets at risk. #MiniShaiHulud #actions-cool/issues-helper #actions-cool/maintain-one-comment

Keypoints

  • Two compromised GitHub Actions were re-enabled with their malicious release tags intact.
  • Workflows referencing actions-cool/issues-helper and actions-cool/maintain-one-comment could download and run the old payload.
  • The original Mini Shai-Hulud campaign affected 323 npm packages and 639 package versions.
  • The malware targeted developer tokens, credentials, and CI/CD secrets.
  • Socket advised removing the actions, pinning a verified clean commit, and rotating any exposed secrets.

Read More: https://www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/