Home / Sep 28, 2026 / Story
0
#4 BleepingComputer general September 26, 2026 at 14:19 UTC

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

By Bill Toulas

AI Summary

Two GitHub Actions compromised in the 'Mini Shai-Hulud' supply chain campaign were re-enabled by their maintainer and remained live with malicious payloads for over a week, extending the window of exposure for any CI/CD pipelines referencing those actions. The incident illustrates the persistent risk of supply chain compromise in GitHub Actions, where reactivation by an original maintainer can silently reintroduce malicious code. Security teams using third-party Actions should audit their workflows and pin actions to specific commit SHAs rather than mutable tags.

Relevance score: 78.0/100

# More from September 28