← All articles

Compromised GitHub Actions came back online still executing Mini Shai-Hulud credential malware

Socket reported that two GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were disabled a second time after their repositories became accessible again on September 16, months after being compromised in the May Mini Shai-Hulud campaign. When the repositories returned, their release tags were not cleaned up and still pointed to the malicious content introduced on May 18, so any workflow referencing either action by a version tag resumed downloading and executing the payload on its next run. The original May 18 compromise ran code that harvested credentials from CI/CD pipelines and exfiltrated them, activity linked to the Mini Shai-Hulud cluster through a shared exfiltration domain. GitHub has again disabled both repositories.

Check
Audit workflows for references to the two actions-cool actions, pin actions to trusted commit hashes, and rotate any CI/CD secrets exposed since September 16.
Affected
Pipelines referencing the affected actions-cool actions by version tag re-ran the May 18 payload after September 16, harvesting and exfiltrating CI/CD credentials.
Fix
Remove or repin the actions to vetted commits, rotate pipeline secrets, and prefer commit-hash pinning over mutable version tags for third-party actions.