Two GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were re-enabled after a Mini Shai-Hulud compromise and continued serving malicious code for more than a week. The exposure could have affected workflows that referenced the actions by mutable tags, putting developer tokens, credentials, and CI/CD secrets at risk. #MiniShaiHulud #actions-cool/issues-helper #actions-cool/maintain-one-comment
Keypoints
- Two compromised GitHub Actions were re-enabled with their malicious release tags intact.
- Workflows referencing actions-cool/issues-helper and actions-cool/maintain-one-comment could download and run the old payload.
- The original Mini Shai-Hulud campaign affected 323 npm packages and 639 package versions.
- The malware targeted developer tokens, credentials, and CI/CD secrets.
- Socket advised removing the actions, pinning a verified clean commit, and rotating any exposed secrets.