Two GitHub Actions repositories belonging to the user actions-cool have been disabled again after briefly becoming accessible last week. The action files were originally compromised during the May 2026 Mini Shai‑Hulud malware campaign, and the repositories were restored to restricted status a few months later.
The affected actions are actions-cool/issues-helper and actions-cool/maintain-one-comment. Both projects are hosted on GitHub, a platform that provides version control and continuous‑integration services for developers worldwide.
When users attempt to view either repository, GitHub displays the following notice:
Access to this
The truncated message indicates that the repositories are currently inaccessible, likely due to a security review or ongoing remediation efforts. No further details have been released by the repository owner or GitHub at this time.
The Mini Shai‑Hulud campaign, which began in May 2026, targeted a range of open‑source projects by injecting malicious code into GitHub Actions. The incident prompted GitHub to temporarily disable several affected repositories and to issue guidance on how to detect and remediate compromised workflows.
GitHub has not yet announced a timeline for when the actions-cool repositories will be re‑enabled. Users who rely on these actions are advised to monitor GitHub’s official communications for updates.
<small>Source: The Hacker News — read the original story there.</small>