CYBERSECURITYTRACKER
TRACKING7,719 stories in this site build1,668 vulnerability news stories in this site build
Permanent story citation

Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8514

As cited

Copy frozen at (site build).

threat intel

Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud

Two GitHub Actions repositories (issues-helper and maintain-one-comment) were compromised during the May 2026 Mini Shai-Hulud campaign, disabled by GitHub on May 19, 2026, and then re-enabled on September 16, 2026 with malicious code still present in their release tags. Any workflow referencing these actions by version tag rather than commit SHA automatically executed the payload again upon their next scheduled or event-triggered run, affecting approximately 15,000 dependent repositories without requiring further threat actor intervention.

Why it matters: DevOps teams and open source maintainers using actions-cool/issues-helper or actions-cool/maintain-one-comment by tag reference have likely already executed compromised code in their CI/CD pipelines; immediate action is required to identify affected workflows, rotate exposed secrets, and pin all third-party actions to verified commit SHAs.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary