GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Summary
Two third-party GitHub Actions were compromised in a Mini Shai-Hulud campaign and remained accessible for over a week with malicious code. The maintainer re-enabled them, allowing attackers to potentially access user data through the compromised actions.
IFF Assessment
FOE
The article describes a security incident where compromised GitHub Actions were re-enabled, posing a risk to users and allowing potential data exfiltration.
Defender Context
This incident highlights the risks associated with third-party integrations in CI/CD pipelines. Defenders should monitor for suspicious activity in their GitHub Actions, review the permissions granted to third-party actions, and ensure prompt patching or removal of compromised components.