Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Summary

Two GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, have been disabled for a second time after their repositories became accessible again. These actions were previously compromised during the Mini Shai-Hulud malware campaign in May 2026 and have resumed executing the malicious payload.

IFF Assessment

FOE

The article reports on the re-emergence of malware associated with compromised GitHub Actions, indicating a continued threat to the software supply chain.

Defender Context

This incident highlights the persistent risks associated with compromised software supply chains, particularly within popular development platforms like GitHub. Defenders must remain vigilant about the integrity of third-party code and continuously monitor for re-emergence of known malicious components.

Read Full Story →