GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Summary

Two third-party GitHub Actions were compromised in a Mini Shai-Hulud campaign and remained accessible for over a week with malicious code. The maintainer re-enabled them, allowing attackers to potentially access user data through the compromised actions.

IFF Assessment

FOE

The article describes a security incident where compromised GitHub Actions were re-enabled, posing a risk to users and allowing potential data exfiltration.

Defender Context

This incident highlights the risks associated with third-party integrations in CI/CD pipelines. Defenders should monitor for suspicious activity in their GitHub Actions, review the permissions granted to third-party actions, and ensure prompt patching or removal of compromised components.

Read Full Story →