MediumII Cyber Warfare & Critical Infrastructure25 September 2026, Friday
2 GitHub Actions compromised in May went back online with malicious code: around 15,000 repositories depend on them, exposure lasted 7 hours to 9 days
According to Socket researchers, the actions-cool/issues-helper and actions-cool/maintain-one-comment actions, compromised in the Mini Shai-Hulud campaign on 18 May, became accessible again on 16 September and re-ran the payload in workflows calling them by version tag. GitHub has taken both repositories down again; according to BleepingComputer, around 15,000 repositories depend on issues-helper.
According to a report by The Hacker News on 25 September, two GitHub Actions that automate repository and maintenance tasks were left uncleaned after the initial compromise on 18 May 2026 and became accessible again on 16 September. According to Socket researcher Karlo Zanki, every workflow referencing these actions by version tag downloaded and executed the payload again on its next run. The payload harvests sensitive credentials from CI/CD pipelines and sends them to the attacker's server at the t.m-kosche[.]com domain. Philipp Burckhardt, Socket's head of threat intelligence, linked the activity to the Mini Shai-Hulud cluster on the basis of infrastructure overlap. GitHub took the two repositories down again for violating its terms of service; why the repositories were reopened is unknown. References pinned by SHA to a commit predating 18 May are safe.
According to a BleepingComputer report on 26 September, the exposure window ran from 11:09 on 16 September to 18:16 on 25 September (GMT+2), i.e. roughly 9 days, and the two actions were disabled again on 25 September. The Hacker News, however, puts the re-enablement between 11:09 and 18:16 on 16 September; this gap between the two sources, 7 hours versus 9 days, has not been resolved. According to BleepingComputer, the May wave affected 639 versions of 323 npm packages and around 15,000 repositories depend on issues-helper; how many workflows actually executed the payload during this window could not be verified. Because the credential-exfiltration payload targets CI/CD secrets, affected projects need to rotate their cloud, package registry and deployment keys.
Talay assessment
Bottom line
The incident shows that in software supply chain attacks a removed component can return without being cleaned: 2 actions taken down in May ran again in September with the same payload. Workflows relying on version tags were exposed once more; those using SHA pinning were protected. Until it is clear whether the exposure lasted 7 hours or 9 days, the scale of the impact cannot be measured; the most likely outcome is a wave of credential rotation and a tightening of the platform's reinstatement checks.
Likely effects
- Software supply chainNegativeWeeks
Among the roughly 15,000 dependent repositories, those calling the actions by version tag may have lost their CI/CD secrets again; this raises the risk of cascading compromise of cloud and package registry keys.
- Platform governanceNegative1–6 months
The fact that repositories whose malicious code had not been cleaned could be reopened increases pressure for scrutiny of GitHub's takedown and reinstatement processes.
- TürkiyeNegativeWeeks
Turkish software teams and public projects using GitHub Actions are also at risk if they reference the same actions by version tag; SHA pinning and secret rotation are an urgent control item for local teams too.
Possibilities, ranked
- 1Secret rotation wave60%
Affected projects rotate their keys, and the incident closes with a limited number of verified secondary leaks.
Watch: A statement from Socket or GitHub on the number of affected workflows
- 2Secondary compromises25%
Stolen CI/CD secrets are used to compromise new npm packages or cloud accounts, and the campaign launches a new wave.
Watch: Reports of new npm packages linked to Mini Shai-Hulud infrastructure
- 3Platform rule change15%
GitHub introduces mandatory code review and a SHA pinning warning before removed actions can be reinstated.
Watch: GitHub's official incident statement or a policy update
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- Dependent repos (issues-helper)▼ ~15,000
- npm packages affected in May▼ 323
- Exposure duration▼ 7 hours–9 days