Technology

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Bleeping Computer September 26, 2026 5 views

Advertisement

Two third‑party GitHub Actions that had been compromised in a Mini Shai‑Hulud campaign were re‑enabled by their maintainer, leaving the malicious code still accessible for more than a week.

The actions, which had previously been flagged as part of the Mini Shai‑Hulud threat, were restored to the GitHub marketplace after the maintainer lifted the suspension. Despite the re‑activation, the workflows continue to point to the same malicious payload that was originally identified.

Security researchers noted that the continued availability of these actions means that developers who rely on them could inadvertently incorporate the malware into their own projects. The delay between the discovery of the compromise and the removal of the code has extended the window of exposure for any users who had not yet updated their dependencies.

GitHub’s policy requires maintainers to remove or fix any code that is identified as malicious. In this case, the maintainer’s decision to re‑enable the actions without addressing the underlying threat has raised concerns about the effectiveness of the platform’s incident‑response procedures.

Users are advised to review the dependencies in their repositories and to verify that any third‑party actions they use are free from known vulnerabilities or malicious code. The incident underscores the importance of continuous monitoring and swift remediation in open‑source ecosystems.

<small>Source: Bleeping Computer — read the original story there.</small>

How did this make you feel?

Never miss a story

Get the best of SpeakOX in your inbox. No spam, unsubscribe anytime.

Advertisement

Category
Technology

Advertisement