HackerFeeds

CyberSecurity News

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

The Hacker News
· September 25, 2026

AI summary

Two compromised GitHub Actions, issues-helper and maintain-one-comment, were temporarily accessible again after being disabled months prior due to the Mini Shai-Hulud campaign in May 2026. These actions have now been disabled for a second time. The repositories for these actions are currently inaccessible, displaying an access restriction message. The actions were part of the actions-cool GitHub organization. They were compromised as part of the Mini Shai-Hulud malware campaign. The repositories were taken offline again after regaining accessibility last week.

Read the full article at The Hacker Newsthehackernews.com/2026/09/compromised-github-actions-came-back.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.