Compromised GitHub Actions Reactivated Mini Shai-Hulud Payloads After Repositories Returned Online

· Original article ↗

Summary

Two actions-cool GitHub Actions became accessible again on September 16 with malicious release tags still in place, causing workflows using version tags to resume downloading and executing payloads. GitHub disabled the repositories again.

Key points

  • The two actions-cool repositories were re-enabled on September 16, 2026, and disabled again afterward.
  • Release tags still pointed to malicious code introduced during the May 18 compromise, so workflows referencing the actions by version tag could execute the payload again.
  • The original payload harvested credentials from CI/CD pipelines and exfiltrated them to an attacker-controlled server.
  • Shared exfiltration infrastructure linked the activity to the Mini Shai-Hulud cluster.
  • Workflows pinned to a full commit SHA from before May 18 were not affected by the tag reactivation.
  • Developers should remove affected actions, pin to a known-clean SHA, rotate exposed secrets, and review workflow runs and repository history.

Article Details

Event Type
Reactivation of compromised GitHub Actions through version tags that still pointed to malicious code
Impact
Workflows referencing the affected version tags resumed downloading and executing a credential-harvesting payload when the repositories became accessible again. The code could exfiltrate CI/CD secrets to an attacker-controlled server; the article does not establish how many workflows ran it or how many secrets were exposed.

Indicators of compromise

TypeIndicatorContext
DOMAINt[.]m-kosche[.]comAttacker-controlled exfiltration domain shared by the compromised GitHub Actions workflows and malicious npm packages.

MITRE ATT&CK

Threat Actors

Malware

Vendors

Products

Related Articles