Close Menu
NCIJ Network NCIJ Network
    What's Hot

    NGOs call on Vantara to end all wild animal imports permanently

    September 25, 2026

    Fit-out of NeuConnect’s converter stations in progress

    September 25, 2026

    Wisconsin immigrants can keep using clinics, Head Start and adult education, judge rules

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • NGOs call on Vantara to end all wild animal imports permanently
    • Fit-out of NeuConnect’s converter stations in progress
    • Wisconsin immigrants can keep using clinics, Head Start and adult education, judge rules
    • Morrisons isn’t giving away free food boxes to people who comment on Facebook posts – Full Fact
    • Supreme Court allows Trump to use controversial database to check voter citizenship
    • Pope warns against ‘losing humanity’ to AI machines
    • Jeffrey Donaldson could face more than 10 years in jail for child sexual abuse, court told | Northern Ireland
    • No general election before 2029, Andy Burnham says | Andy Burnham
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 25, 2026Malware / Supply Chain Attack

    Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign.

    The affected GitHub Actions are listed below –

    Visiting either of the repositories now shows the message: “Access to this repository has been disabled by GitHub Staff due to a violation of GitHub’s terms of service. If you are the owner of the repository, you may reach out to GitHub Support for more information.”

    “On September 16, 2026, both repositories became accessible again,” Socket researcher Karlo Zanki said. “Their release tags were not cleaned up first. They still point to the malicious content introduced on May 18, so any workflow that references either action by a version tag resumed downloading and executing the payload on its next run.”

    Cybersecurity

    The two GitHub Actions workflows were originally compromised on May 18, 2026, to run malicious code that harvested sensitive credentials from CI/CD pipelines that ran them and exfiltrated the details to an attacker-controlled server.

    The activity was subsequently linked to the Mini Shai-Hulud activity cluster, citing overlaps in the exfiltration domain (“t.m-kosche[.]com”) used in the GitHub Actions workflows and the npm packages from the @antv ecosystem.

    “That points to the same Mini Shai-Hulud activity cluster, not a separate npm-only incident,” Philipp Burckhardt, head of threat intelligence at Socket, told The Hacker News at the time.

    The repositories were re-enabled on September 16, 2026, at some point between 11:09 a.m. and 6:16 p.m. GMT+2. It’s currently not known why this occurred.

    But the latest development points to another problem: the malicious code remained in the affected codebases and never cleaned up, and all that was required to activate the threat was for the repositories to become downloadable again.

    Given that there are still several workflows that use the two GitHub Actions, the exposure could have led to severe software supply chain security risks without the need for the threat actors to use a new exploit or set up new infrastructure.

    “Both actions automate issue and comment housekeeping, such as closing inactive issues, checking newly opened ones, or keeping a single bot comment up to date,” Socket said.

    “The workflows that call them usually run on a daily schedule or whenever someone opens an issue or pull request. In practice, most affected repositories probably ran the payload within a day of the re-enablement, with no further action needed from the threat actor.”

    Cybersecurity

    The issue does not impact workflows that pin either action to the full commit SHA of a version from before May 18, 2026. Developers are recommended to carry out the following steps –

    • Locate every reference to the affected actions and treat “actions-cool/issues-helper@v2.2.1” as affected.
    • Remove the actions and pin them to a known-clean SHA that predates May 18, 2026.
    • Rotate all exposed secrets.
    • Review workflow run history and check for newly successful runs after a prolonged period of Set up job failures.
    • Audit repository history for unexpected commits after September 16, 2026.

    “Most supply chain incidents involve something new: a newly published malicious version, a newly hijacked account, or a newly injected workflow,” Zanki said. “This one did not. No new code was published and no configuration was changed.”

    “This incident shows that a mutable tag can be compromised, contained, and then reactivated without any change to your own workflow file. SHA pinning removes that dependency on the upstream repository’s state.”

    Actions Compromised Executing GitHub Malware mini online resumed ShaiHulud
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions

    OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

    Fixing Flock: The controls needed now that misuse patterns are clear

    The SOC Doesn’t Need to Start Over with Every Alert

    Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

    Microsoft: Recent Windows updates cause desktop loading issues

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    NGOs call on Vantara to end all wild animal imports permanently

    September 25, 2026

    Fit-out of NeuConnect’s converter stations in progress

    September 25, 2026

    Wisconsin immigrants can keep using clinics, Head Start and adult education, judge rules

    September 25, 2026

    Morrisons isn’t giving away free food boxes to people who comment on Facebook posts – Full Fact

    September 25, 2026
    Latest Posts

    A Growing Number of Election Deniers Hold Key Local Roles in Midterms

    August 6, 2026

    Lithuania warns Russia could be considering possible ‘false flag’ strike on the Baltics – Europe live | Europe

    August 6, 2026

    Will Mamdani’s city-run grocery stores require ID to shop? Here’s the truth

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    NGOs call on Vantara to end all wild animal imports permanently

    September 25, 2026

    Fit-out of NeuConnect’s converter stations in progress

    September 25, 2026

    Wisconsin immigrants can keep using clinics, Head Start and adult education, judge rules

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.