CONNECT WITH US
Cyber Security

Cyber Security

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

The Hacker News logo

Published on

Add as a preferred source on Google
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign.

"On September 16, 2026, both repositories became accessible again," Socket researcher Karlo Zanki said. "Their release tags were not cleaned up first. They still point to the malicious content introduced on May 18, so any workflow that references either action by a version tag resumed downloading and executing the payload on its next run."

The two GitHub Actions workflows were originally compromised on May 18, 2026, to run malicious code that harvested sensitive credentials from CI/CD pipelines that ran them and exfiltrated the details to an attacker-controlled server.

The activity was subsequently linked to the Mini Shai-Hulud activity cluster, citing overlaps in the exfiltration domain ("t.m-kosche[.]com") used in the GitHub Actions workflows and the npm packages from the @antv ecosystem.

"That points to the same Mini Shai-Hulud activity cluster, not a separate npm-only incident," Philipp Burckhardt, head of threat intelligence at Socket, told The Hacker News at the time.

The repositories were re-enabled on September 16, 2026, at some point between 11:09 a.m. and 6:16 p.m. GMT+2. It's currently not known why this occurred.

But the latest development points to another problem: the malicious code remained in the affected codebases and never cleaned up, and all that was required to activate the threat was for the repositories to become downloadable again.

Given that there are still several workflows that use the two GitHub Actions, the exposure could have led to severe software supply chain security risks without the need for the threat actors to use a new exploit or set up new infrastructure.


Source link

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We TheMorningPulse.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It's possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.