Active Exploitation Alert: Compromised GitHub Actions Reactivated, Resuming Mini Shai-Hulud Malware Supply Chain Attacks in CI/CD Workflows

Active Exploitation Alert: Compromised GitHub Actions Reactivated, Resuming Mini Shai-Hulud Malware Supply Chain Attacks in CI/CD Workflows

Executive Summary

In September 2026, the cybersecurity community observed a significant resurgence of the Mini Shai-Hulud malware campaign, triggered by the unexpected reactivation of two previously compromised GitHub Actions: actions-cool/issues-helper and actions-cool/maintain-one-comment. These actions, which had been disabled following their exploitation in May 2026, were brought back online without remediation of malicious release tags. As a result, any downstream continuous integration and deployment (CI/CD) workflows referencing these actions resumed executing credential-stealing malware, exposing sensitive secrets and tokens to threat actors. This incident underscores the persistent risks inherent in software supply chains, particularly the dangers of mutable dependencies and the critical need for robust dependency management in CI/CD environments.

Threat Actor Profile

The threat activity is attributed to the Mini Shai-Hulud cluster, a group previously linked to sophisticated supply chain attacks targeting open-source ecosystems. While no specific nation-state or advanced persistent threat (APT) group has been formally identified, the tactics, techniques, and procedures (TTPs) observed align with those used in prior npm package compromises, notably within the @antv ecosystem. The actors demonstrate a high degree of automation and a deep understanding of CI/CD pipeline mechanics, leveraging the trust inherent in open-source workflows to propagate malicious payloads. Their operational infrastructure includes the exfiltration domain t.m-kosche[.]com, which has been consistently used for credential harvesting across multiple campaigns.

Technical Analysis of Malware/TTPs

The technical vector exploited mutable tags in GitHub Actions repositories. In May 2026, attackers injected malicious code into the actions-cool/issues-helper and actions-cool/maintain-one-comment repositories. This code was designed to execute automatically in any workflow referencing the compromised tags, such as v2.2.1 or later. The payload harvested environment variables, secrets, and tokens from the CI/CD context and transmitted them to the attacker-controlled domain t.m-kosche[.]com.

The attack chain unfolded as follows: initially, the malicious code was introduced via a commit to the action’s repository. Any downstream project referencing the affected tag (rather than a specific commit SHA) would, upon workflow execution, download and run the compromised code. When the repositories were disabled, workflows failed to fetch the actions, halting the attack. However, upon re-enablement on September 16, 2026, without removal of the malicious tags, all dependent workflows resumed execution of the malware, leading to a new wave of credential exfiltration.

The malware’s TTPs map to several MITRE ATT&CK techniques, including T1195.002 (Supply Chain Compromise: Compromise Software Dependencies and Development Tools), T1557 (Adversary-in-the-Middle) for credential harvesting, and T1041 (Exfiltration Over C2 Channel). The attack did not require new infrastructure or code changes post-compromise; the mere act of re-enabling the repositories was sufficient to reactivate the threat.

Exploitation in the Wild

The exploitation was widespread and automated. Any organization or developer with workflows referencing the affected actions by tag (rather than by immutable SHA) was at risk. Upon repository reactivation, these workflows automatically fetched and executed the malicious payload, often without any user intervention or awareness. The attack was particularly insidious because it leveraged the default behavior of GitHub Actions, where tags are mutable and can be updated to point to new (potentially malicious) code.

The Mini Shai-Hulud cluster has a history of targeting popular open-source projects and dependencies, maximizing the blast radius of their campaigns. In this instance, the attack vector extended beyond the initial compromise window, as the malicious code persisted in the repository tags. The reactivation event demonstrates how attackers can achieve long-term persistence in the software supply chain, exploiting the trust and automation inherent in modern DevOps practices.

Victimology and Targeting

Victims included any organizations, open-source projects, or individual developers whose CI/CD workflows referenced actions-cool/issues-helper or actions-cool/maintain-one-comment by tag after May 18, 2026. The attack was not limited to a specific sector or geography; rather, it targeted the broad ecosystem of GitHub users leveraging these popular actions. The credential theft exposed secrets, tokens, and potentially sensitive environment variables, which could be leveraged for further lateral movement, privilege escalation, or supply chain attacks against downstream dependencies and partners.

The campaign’s indiscriminate nature, combined with the popularity of the affected actions, suggests a high likelihood of secondary impacts, including compromised npm packages, unauthorized access to private repositories, and potential exposure of proprietary code or infrastructure secrets.

Mitigation and Countermeasures

Immediate action is required to contain and remediate the threat. Organizations must audit all repositories and workflows for references to actions-cool/issues-helper and actions-cool/maintain-one-comment. Any usage of these actions by tag (e.g., @v2.2.1 or later) should be treated as compromised. The recommended remediation steps are as follows: remove or replace the affected actions in all workflows, or pin dependencies to a known-clean commit SHA predating May 18, 2026. Rotate all secrets, tokens, and credentials that may have been exposed via affected workflows. Review workflow run histories for anomalous activity, particularly successful runs following a period of failures after September 16, 2026. Audit repository histories for unexpected commits or changes post-reactivation.

To prevent future incidents, organizations should enforce strict dependency management policies, avoiding mutable tags in third-party actions and always pinning to specific commit SHAs. Continuous monitoring for changes in previously disabled or compromised dependencies is essential. Implementing automated supply chain security tools and integrating threat intelligence feeds can further enhance detection and response capabilities.

References

The following sources provide additional technical details and context for this incident: The Hacker News: Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware, A researcher at Socket shared on LinkedIn: Compromised GitHub Actions Came Back Online, Vulners Threat Intelligence Summary: THN:916483892BA74DDD063D2160D1A3CE5C, Mini Shai-Hulud npm Campaign Analysis: SafeDep.io, MITRE ATT&CK T1195.002: attack.mitre.org.

About Rescana

Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to continuously monitor, assess, and mitigate cyber risks across their digital supply chains. Our advanced analytics and threat intelligence capabilities empower security teams to proactively identify vulnerabilities, enforce best practices, and respond rapidly to emerging threats. For more information about how Rescana can help secure your organization’s ecosystem, or for any questions regarding this advisory, please contact us at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.