#4
BleepingComputer
general
September 26, 2026 at 14:19 UTC
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
By Bill Toulas
AI Summary
Two GitHub Actions compromised in the 'Mini Shai-Hulud' supply chain campaign were re-enabled by their maintainer and remained live with malicious payloads for over a week, extending the window of exposure for any CI/CD pipelines referencing those actions. The incident illustrates the persistent risk of supply chain compromise in GitHub Actions, where reactivation by an original maintainer can silently reintroduce malicious code. Security teams using third-party Actions should audit their workflows and pin actions to specific commit SHAs rather than mutable tags.
Relevance score: 78.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →