Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Two GitHub Actions from the actions-cool project were disabled again after becoming accessible and reactivating malicious payloads tied to the May 2026 Mini Shai-Hulud campaign. The incident highlights how mutable version tags can silently reintroduce supply chain risk, and why SHA pinning is critical for protection. #actions-cool #MiniShaiHulud #GitHubActions

Keypoints

  • Two actions-cool GitHub Actions were disabled again after being re-enabled.
  • The repositories still contained malicious code from the May 18, 2026 compromise.
  • Version tags pointed to the malicious content and restarted payload delivery.
  • The activity was linked to the Mini Shai-Hulud cluster through shared infrastructure.
  • Developers should remove the actions, pin to a clean SHA, rotate secrets, and review workflow history.

Read More: https://thehackernews.com/2026/09/compromised-github-actions-came-back.html