Home › Intelligence › Brief
BREACH BRIEF 🟠 High ThreatIntel

Compromised GitHub Actions Re‑enabled, Re‑exposing CI/CD Pipelines to Mini Shai‑Hulud Malware

Two third‑party GitHub Actions were re‑enabled after a prior supply‑chain compromise, still pointing to the Mini Shai‑Hulud payload. Developers using mutable tags could have downloaded the malware again, highlighting the need for continuous third‑party risk monitoring and immutable dependency pinning.

Verisq™ Intelligence · 📅 September 26, 2026 · 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

Compromised GitHub Actions Re‑enabled, Re‑exposing CI/CD Pipelines to Mini Shai‑Hulud Malware

What Happened — Two third‑party GitHub Actions that were previously removed after a supply‑chain compromise were re‑enabled by their maintainer on 16 Sept 2026. The actions still pointed to the malicious “Mini Shai‑Hulud” payload introduced on 18 May 2026, causing any workflow that referenced the mutable tags to download and execute the malware again until the actions were disabled on 25 Sept 2026.

Why It Matters for Trust & Control Assurance

  • Continuous control‑assurance programs require ongoing verification that third‑party components are clean; re‑enabling compromised actions defeats that safeguard.
  • Pinning dependencies to immutable commits and maintaining audit‑ready evidence of remediation are core controls that prevent hidden re‑introduction of malicious code.
  • The incident underscores the need for automated vendor‑risk monitoring that surfaces stale or mutable tags across the software supply chain.

Who Is Affected – Developers and DevOps teams using GitHub Actions, particularly those in SaaS, cloud‑native, and open‑source ecosystems.

Recommended Actions –

  1. Search all repositories for references to actions-cool/issues-helper and actions-cool/maintain-one-comment.
  2. Replace mutable tags with pinned, verified commits or remove the actions entirely.
  3. Rotate any CI/CD secrets (tokens, credentials) that may have been exposed during the window of re‑activation.

Source: BleepingComputer

Technical Notes – The payload targets developer tokens, credentials, and CI/CD secrets. It was delivered via the index.js file of the compromised actions. No CVE is associated; the risk stems from supply‑chain dependency mis‑management. Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/ ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →