Mini Shai-Hulud: actions-cool GitHub Actions re-enabled 16 Sep with malicious tags; disabled again 25 Sep (Socket)
Socket (24 September 2026; update 25 Sep) documents that GitHub Actions actions-cool/issues-helper and actions-cool/maintain-one-comment — compromised in the May 2026 Mini Shai-Hulud campaign and disabled by GitHub on 19 May — became downloadable again on 16 September 2026 without cleaning release tags. Tags still pointed at the May 18 malicious commits, so workflows referencing either action by mutable version tag (e.g. @v2.2.1) resumed fetching and executing the payload (Bun install + obfuscated index.js; credential harvest / exfil cluster overlap with t.m-kosche[.]com). issues-helper alone has ~15,000 dependent repositories on GitHub's dependency graph; housekeeping workflows often run daily or on issue/PR events, so many repos likely re-ran the payload within a day of re-enablement with no further attacker action. SHA-pinned clean pre-May-18 commits were not affected. Socket update 25 Sep: both repositories disabled again by GitHub Staff (ToS); tag-referenced workflows now fail at job setup instead of running the payload. Distinct from desk card shai-hulud-ai-session-20260916 (Mandiant AI coding-assistant session worm). Primary: Socket; wire: The Hacker News 25 Sep 2026.
- Product
- GitHub Actions: actions-cool/issues-helper; actions-cool/maintain-one-comment
- Versions
- Tag refs (e.g. @v2.2.1) resolving to May 18 2026 malicious commits; SHA pins to pre-May-18 clean commits unaffected
- Exploited in Australia?
- unknown
- Patch to
- Search workflows for actions-cool/issues-helper@ and actions-cool/maintain-one-comment@; remove or pin to verified pre-May-18 commit SHA; rotate secrets reachable by any tag-based run on/after 16 Sep 2026; review runs that flipped from seconds-long Set up job failures to multi-minute successes; audit unexpected commits after 16 Sep; pin all third-party Actions to full SHAs
Primary: Socket — Re-Enabled GitHub Actions expose Mini Shai-Hulud (24 Sep 2026; update 25 Sep) · Vendor: Socket (researcher primary) · The Hacker News — compromised Actions came back (25 Sep 2026)
