Compromised GitHub Actions Reactivated, Resuming Malware Attacks

Two disabled GitHub Actions came back online in September 2026 without removing malicious tags, automatically re-executing credential-stealing Mini Shai-Hulud malware in downstream workflows.

Read as article

Compromised GitHub Actions Reactivated, Resuming Malware Attacks

By @sharedot · · 6 pages

Two disabled GitHub Actions came back online in September 2026 without removing malicious tags, automatically re-executing credential-stealing Mini Shai-Hulud malware in downstream workflows.

Disabled malware came back to life

In May 2026, attackers injected credential-stealing code into two popular GitHub Actions — actions-cool/issues-helper and actions-cool/maintain-one-comment — via malicious release tags such as v2.2.1. When the repositories were disabled, workflows that referenced them failed to fetch the actions and the attack stalled. According to Rescana, the repositories were re-enabled on September 16, 2026 without the malicious tags being remediated, so every downstream CI/CD workflow still pointing at the compromised tags automatically resumed executing the Mini Shai-Hulud payload, exfiltrating secrets to the attacker-controlled domain t.m-kosche[.]com with no new code or infrastructure required.

Why the reversal caught maintainers off guard

The surprising twist is that disabling a compromised dependency was treated as containment, and its reactivation undid that containment silently. Rescana notes the attack exploited GitHub Actions' default behavior, where tags are mutable and can be repointed to new code, so teams pinning by tag rather than by immutable commit SHA had no way to know the tag they trusted now led back to malware. The persistence survived a four-month dormancy: the malicious code sat in the repository tags the entire time, and the mere administrative act of re-enabling the repos was enough to restart credential harvesting across an indiscriminate set of victims.

The evidence and the broader pattern

Rescana maps the TTPs to MITRE ATT&CK techniques including T1195.002 (compromise of software dependencies and development tools), T1557 for credential harvesting, and T1041 for exfiltration over a C2 channel, attributing the activity to the Mini Shai-Hulud cluster previously linked to npm compromises in the @antv ecosystem. According to Qualys, the May 19 wave of Mini Shai-Hulud compromised 639 package versions across 323 packages in the @antv ecosystem, targeting GITHUB_TOKEN, AWS keys, KUBECONFIG, and VAULT_TOKEN, and by shifting execution to the preinstall lifecycle hook, credentials could be stolen even if an installation was cancelled. Qualys argues this confirms a credential-first kill chain in which a package install becomes a cloud breach.

Stakes and what developers should do now

Because stolen secrets and tokens can enable lateral movement, privilege escalation, and further supply chain attacks, the practical stakes extend well past the two named actions. Rescana recommends auditing all workflows for references to actions-cool/issues-helper and actions-cool/maintain-one-comment, treating any tag-based usage (such as @v2.2.1 or later) as compromised, pinning dependencies to known-clean commit SHAs predating May 18, 2026, rotating all potentially exposed secrets, and reviewing run histories for successful runs that followed failures after September 16. Qualys adds that containment must go beyond removing packages: rotate every credential the affected runner could access, use short-lived OIDC-based credentials instead of long-lived keys, and investigate cloud activity across the exposure window.

Sources

  1. rescana.com › Active Exploitation Alert: Compromised GitHub Actions Reactivated, Resuming Mini Shai-Hulud Malware Supply Chain Attacks in CI/CD Workflows
  2. blog.qualys.com › The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches

More on Programming