Between 11:09 and 18:16 Central European time on 16 September 2026, two GitHub Actions repositories that had been disabled since 19 May were re-enabled. Both belonged to the actions-cool organisation, and both still carried the release tags that the Mini Shai-Hulud campaign had poisoned on 18 May with an obfuscated credential stealer. No new code was published and no configuration changed. Workflows referencing issues-helper or maintain-one-comment by tag simply resumed executing the May payload on their next run. GitHub disabled the repositories again on 25 September, citing a terms-of-service violation.
Socket researcher Karlo Zanki identified the re-enablement. About 15,000 repositories depend on issues-helper according to GitHub’s own dependency graph. How many reference it by mutable tag rather than pinned commit, and how many workflows ran in the nine days, neither Socket nor GitHub could say. BleepingComputer’s assessment was that most affected repositories probably ran the payload within a day.
What The Payload Does
The action’s wrapper installs the Bun runtime and executes an index.js inside the CI runner, with the workflow’s GITHUB_TOKEN and any secrets the job exposes. The May code harvests developer tokens, cloud and registry credentials and pipeline secrets and sends them to an attacker server. The exfiltration domain is shared with the compromised npm packages from the same campaign, which the corpus filed at 26-0520 and 26-0606. The campaign that poisoned 323 packages in May got a second run in September without lifting a finger.
The Mutable Tag
A workflow that says issues-helper@v2.2.1 trusts whatever commit that tag points to today. A workflow that pins a commit hash trusts one specific piece of code. The first is how most of the ecosystem is written, because it is how the documentation shows it. A disabled repository protects tag-pinned users only while it stays disabled, and this file records what happens when the platform’s only control is a switch that somebody flipped back.
The Question GitHub Has Not Answered
Why the repositories were re-enabled, whether by an appeal process or an error, and why the poisoned tags were not removed before restoration, GitHub has not said in public. The corpus filed at 22-0412 the platform’s own account of stolen OAuth tokens four years earlier. Here the platform was not breached. It restored a known-malicious artefact to a registry that thousands of pipelines pull from automatically, and the remediation advice, rotate every secret available to any workflow that ran between 16 and 25 September, is the cost of that decision.
Compiled from Socket’s analysis and contemporaneous reporting, listed below. The re-enablement window and dependent count are Socket’s; the payload description is from Socket and BleepingComputer. GitHub had made no public statement in the material reviewed. Graded high. Corrections: corrections@forensicpost.com.