As cited
Copy frozen at (site build).
threat intel
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two GitHub Actions repositories (issues-helper and maintain-one-comment) were compromised during the May 2026 Mini Shai-Hulud campaign, disabled by GitHub on May 19, 2026, and then re-enabled on September 16, 2026 with malicious code still present in their release tags. Any workflow referencing these actions by version tag rather than commit SHA automatically executed the payload again upon their next scheduled or event-triggered run, affecting approximately 15,000 dependent repositories without requiring further threat actor intervention.
Why it matters: DevOps teams and open source maintainers using actions-cool/issues-helper or actions-cool/maintain-one-comment by tag reference have likely already executed compromised code in their CI/CD pipelines; immediate action is required to identify affected workflows, rotate exposed secrets, and pin all third-party actions to verified commit SHAs.
- Source published
- First seen by Cybersecurity Tracker