Mini Shai-Hulud Returns: Compromised GitHub Actions Briefly Re-Enabled, Posing Renewed Supply Chain Risk
Two previously compromised GitHub Actions, linked to the 'Mini Shai-Hulud' supply chain attack, were inadvertently re-enabled last week, months after their initial discovery. This incident exposed CI/CD pipelines to malicious payloads once more, highlighting critical vulnerabilities in mutable tag dependencies and the persistent danger of uncleaned compromised codebases.
Supply chain security has once again been spotlighted by the unexpected re-activation of two **GitHub Actions** that were previously compromised during the **May 2026 Mini Shai-Hulud campaign**. The **actions-cool/issues-helper** and **actions-cool/maintain-one-comment** repositories were briefly accessible again, leading to the potential re-execution of malicious code in affected CI/CD pipelines.
### The Initial Compromise and Re-emergence
The two **GitHub Actions** were originally compromised on May 18, 2026. Attackers injected malicious code designed to harvest sensitive credentials from CI/CD pipelines and exfiltrate them to an attacker-controlled server, specifically using the domain "t.m-kosche[.]com". This activity was subsequently linked to the broader **Mini Shai-Hulud** cluster, which also targeted **npm packages from the @antv ecosystem**.
Following the initial discovery, **GitHub Staff** disabled access to both repositories due to violations of their terms of service.
### A Troubling Re-enablement
However, on September 16, 2026, both repositories became accessible again for an unknown period. As **Socket** researcher **Karlo Zanki** pointed out, the critical issue was that their release tags had not been cleaned up. The tags still pointed to the original malicious content introduced in May, meaning any workflow referencing these actions by version tag immediately resumed downloading and executing the payload upon its next run.

This re-enablement, which occurred between 11:09 a.m. and 6:16 p.m. GMT+2, presented a significant risk. With numerous active workflows still utilizing these **GitHub Actions**, the exposure could have led to widespread software supply chain security breaches without any new exploit or infrastructure setup by the threat actors.
### The Peril of Mutable Tags
**Socket** emphasized that this incident differed from typical supply chain attacks. "Most supply chain incidents involve something new: a newly published malicious version, a newly hijacked account, or a newly injected workflow," Zanki stated. "This one did not. No new code was published and no configuration was changed." The core problem lay in the mutable nature of the tags, which, once compromised, could be re-activated without any changes to a user's workflow file.

### Recommendations for Developers
To mitigate similar risks and address potential exposure from this incident, developers are strongly advised to take the following steps:
* **Locate References:** Identify all instances where the affected actions are used, treating "actions-cool/[email protected]" as compromised.
* **Remove and Pin:** Remove the compromised actions and re-pin them to a known-clean commit SHA that predates May 18, 2026.
* **Rotate Secrets:** Immediately rotate all secrets that may have been exposed through CI/CD pipelines running these actions.
* **Review Workflow History:** Audit workflow run histories for any newly successful runs after a period of "Set up job failures," which could indicate re-activation.
* **Audit Repository History:** Check repository histories for any unexpected commits made after September 16, 2026.
This incident serves as a stark reminder of the importance of **SHA pinning** in CI/CD workflows, which removes the dependency on the upstream repository's mutable state and provides a more robust defense against supply chain attacks.