Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitHub Actions Resurface with Mini Shai-Hulud Malware

GitHub Actions Resurface with Mini Shai-Hulud Malware

Posted on September 25, 2026 By CWS

Two GitHub Actions known as actions-cool were once again disabled after briefly becoming accessible last week. These repositories, originally compromised in the Mini Shai-Hulud campaign of May 2026, were re-enabled, raising concerns in the cybersecurity community.

Re-activation of Compromised Repositories

Last seen online on September 16, 2026, these repositories were not cleansed of their malicious content before becoming accessible again. This allowed workflows referencing specific version tags to inadvertently download and execute harmful payloads. Karlo Zanki, a researcher at Socket, highlighted the issue, noting that the release tags were unchanged, facilitating the resumption of malware execution.

The original compromise of these GitHub Actions involved the execution of malicious code that aimed to gather sensitive credentials from CI/CD pipelines. This data was then transmitted to a server controlled by the attackers. The attack was traced back to the Mini Shai-Hulud activity cluster, characterized by shared exfiltration domains and links to npm packages from the @antv ecosystem.

Potential Risks and Developer Guidance

The reactivation of these repositories without proper cleanup suggests significant risks for software supply chain security. The malicious code remained intact, and the only requirement for its activation was for the repositories to be downloadable once more. The compromised Actions were primarily used for automating tasks such as managing issues and comments in repositories, potentially impacting many workflows.

Developers are advised to take immediate action to mitigate these risks. They should identify all references to the affected actions, replace them with clean SHAs predating May 18, 2026, and rotate any exposed secrets. Additionally, auditing the workflow run history for unusual activity and reviewing repository history for unexpected changes after September 16, 2026, are crucial steps in securing their environments.

Understanding the Implications

Unlike typical supply chain attacks, this incident lacked new code or configuration changes. Instead, it underscores the vulnerability of mutable tags in workflows. As Zanki pointed out, the ability to reactivate compromised code without altering a workflow highlights the importance of SHA pinning to prevent such dependencies on the state of upstream repositories.

The resurfacing of the Mini Shai-Hulud malware serves as a critical reminder for developers and organizations to maintain vigilance and adopt best practices in securing their software supply chains. Ensuring robust security measures can mitigate the risks posed by similar incidents in the future.

The Hacker News Tags:CI/CD pipelines, code repositories, Cybersecurity, GitHub, Malware, Mini Shai-Hulud, SHA pinning, Software Security, supply chain attack, Threat Actors

Post navigation

Previous Post: Cybersecurity Updates: Clop Site Seized, AI Key Threats
Next Post: PamStealer Malware Evasive Tactics on macOS

Related Posts

Stealit Malware Abuses Node.js Single Executable Feature via Game and VPN Installers Stealit Malware Abuses Node.js Single Executable Feature via Game and VPN Installers The Hacker News
Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails The Hacker News
Malicious Telnyx Versions on PyPI: Audio Steganography Attack Malicious Telnyx Versions on PyPI: Audio Steganography Attack The Hacker News
U.S. Sanctions 10 North Korean Entities for Laundering .7M in Crypto and IT Fraud U.S. Sanctions 10 North Korean Entities for Laundering $12.7M in Crypto and IT Fraud The Hacker News
SEC Files Charges Over  Million Crypto Scam Using Fake AI-Themed Investment Tips SEC Files Charges Over $14 Million Crypto Scam Using Fake AI-Themed Investment Tips The Hacker News
Hidden Setting in Muse AI Poses Security Threat Hidden Setting in Muse AI Poses Security Threat The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • PamStealer Malware Evasive Tactics on macOS
  • GitHub Actions Resurface with Mini Shai-Hulud Malware
  • Cybersecurity Updates: Clop Site Seized, AI Key Threats
  • North Korea Implicated in Major Bitget Crypto Theft
  • CISA Unveils 2026 Election Security Plan Amid Cyber Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • PamStealer Malware Evasive Tactics on macOS
  • GitHub Actions Resurface with Mini Shai-Hulud Malware
  • Cybersecurity Updates: Clop Site Seized, AI Key Threats
  • North Korea Implicated in Major Bitget Crypto Theft
  • CISA Unveils 2026 Election Security Plan Amid Cyber Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark