Compromised GitHub Actions Re-enabled With Malicious Mini Shai-Hulud Payload
Two third-party GitHub Actions compromised in the May Mini Shai-Hulud campaign are re-enabled by their maintainer and remain accessible for more than a week despite still pointing to malicious code. GitHub's security team removes actions-cool/issues-helper and actions-cool/maintain-one-comment after the May 18 compromise, preventing downstream workflows from downloading malware.
According to researchers at application security company Socket, the two actions become active again on September 16 with the same release tags, causing workflows that reference them to download and execute the old payload. The tags still resolve to a commit containing an obfuscated payload inside the index.js file, so any workflow using a version tag resumes running the malicious code on its next run. The Mini Shai-Hulud attack in May affects 323 packages and 639 package versions on npm, targeting developer tokens, credentials, and CI/CD secrets.
Socket notes that GitHub's dependency graph lists about 15,000 repositories depending on issues-helper, though not all are compromised. The impacted actions are those running almost daily, as they support issue-housekeeping needs. On September 25, both actions are disabled again, causing workflows that reference them to fail instead of running the payload. Socket recommends removing references to both actions or pinning a verified clean commit, reviewing workflow runs since September 16, and rotating secrets accessible to workflows that ran an affected tag.