News / Cybersecurity
Two GitHub Actions Re-Enabled Expose 15,000 Repositories to Mini Shai-Hulud Despite Initial Deactivation Published on 28 September 2026 by Christ-loisele (3 min read)
The actions actions-cool/issues-helper and actions-cool/maintain-one-comment, compromised in May 2026, were re-enabled without cleaning malicious tags, re-exposing thousands of CI/CD workflows to malware capable of exfiltrating tokens and secrets. GitHub deactivated them again after nine days of exposure.
Video: Mini Shai-Hulud: The Worm That Devoured Dev Tools (The Pleopod Times, YouTube)
An intact payload re-enabled without explanation
The two GitHub actions, actions-cool/issues-helper and actions-cool/maintain-one-comment , were re-enabled on September 16, 2026, by their maintainer, despite having been disabled by GitHub on May 19, 2026, as part of the Mini Shai-Hulud campaign. According to BleepingComputer , the version tags of these actions still pointed to a malicious commit introduced on May 18, 2026, containing an obfuscated payload in index.js. This code, executed during CI/CD workflows, downloaded and installed malware capable of stealing GitHub tokens, cloud credentials (AWS, Azure, GCP), and SSH keys, as detailed by Security Arsenal .
The failure to clean the tags before re-enabling allowed workflows referencing these actions via mutable tags (such as @v2.2.1) to re-execute the payload upon their next trigger. GitHub states that 15,000 repositories depend on issues-helper , although not all were necessarily compromised. Workflows pinned to a SHA prior to May 18, 2026, remained protected, highlighting the importance of this practice to mitigate supply-chain attack risks, according to Socket .
Re-enabling the repositories turned a contained threat into a silent and immediate exposure for thousands of dependent projects.
Illustration: Lawing Tech
A persistent malware exploiting daily workflows
The Mini Shai-Hulud malware uses a secret scanning technique inspired by TruffleHog to detect and exfiltrate sensitive credentials from compromised repositories' files and systems. The stolen data is sent to servers controlled by attackers, including endpoints like webhook.site or GitHub repositories named Shai-Hulud , as detailed by Security Arsenal . Unlike a traditional software vulnerability, this campaign relies on a supply-chain compromise (supply-chain compromise ) without an associated CVE.
The compromised actions automate common tasks such as closing inactive issues or updating comments, often executed daily. Their re-enabling thus quickly exposed dependent projects, with logs showing successful executions in 11 minutes compared to 2 seconds of failure before re-enabling (linked to access blocking), according to Socket . The malware can also spread by pushing trojanized npm packages or modifying workflows to maintain persistence.
What this changes here
For businesses and government agencies in Benin and West Africa using GitHub Actions in their CI/CD pipelines, this reactivation highlights two major risks: the importance of systematically verifying third-party dependencies, even after their official deactivation, and the need to pin references to actions on specific commit SHA hashes rather than version tags. Organizations could thus avoid re-executing malicious payloads if a compromised action is reactivated without prior cleanup.
Furthermore, the exfiltration of GitHub tokens (GITHUB_TOKEN) and cloud keys exposes local infrastructures to unauthorized access. An audit of workflows using actions-cool/issues-helper or maintain-one-comment is recommended, particularly for critical projects where sensitive secrets are handled. Finally, this incident underscores that supply-chain attack campaigns, such as Mini Shai-Hulud, can re-emerge without warning , making continuous vigilance essential.
Sources