Desk live·
ForensicPost
Cloud/Supply chain/File 26-0925

GitHub Switched Two Poisoned Actions Back On, and 15,000 Repositories Reran the May Payload

The actions-cool/issues-helper and maintain-one-comment actions were disabled on 19 May after the Mini Shai-Hulud campaign put a credential stealer in their tags. On 16 September they came back, tags untouched. Every workflow pinned to a tag re-ran the payload on its next job until GitHub disabled them again on 25 September.

Constructed geometry · not a chart of case data
JurisdictionUSASan Franciscothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetGitHub Actions dependents
ActorMini Shai-Hulud operators
S. Rosler10 min readConfidence: high3 sources reviewed

Between 11:09 and 18:16 Central European time on 16 September 2026, two GitHub Actions repositories that had been disabled since 19 May were re-enabled. Both belonged to the actions-cool organisation, and both still carried the release tags that the Mini Shai-Hulud campaign had poisoned on 18 May with an obfuscated credential stealer. No new code was published and no configuration changed. Workflows referencing issues-helper or maintain-one-comment by tag simply resumed executing the May payload on their next run. GitHub disabled the repositories again on 25 September, citing a terms-of-service violation.

Socket researcher Karlo Zanki identified the re-enablement. About 15,000 repositories depend on issues-helper according to GitHub’s own dependency graph. How many reference it by mutable tag rather than pinned commit, and how many workflows ran in the nine days, neither Socket nor GitHub could say. BleepingComputer’s assessment was that most affected repositories probably ran the payload within a day.

What The Payload Does

The action’s wrapper installs the Bun runtime and executes an index.js inside the CI runner, with the workflow’s GITHUB_TOKEN and any secrets the job exposes. The May code harvests developer tokens, cloud and registry credentials and pipeline secrets and sends them to an attacker server. The exfiltration domain is shared with the compromised npm packages from the same campaign, which the corpus filed at 26-0520 and 26-0606. The campaign that poisoned 323 packages in May got a second run in September without lifting a finger.

The Mutable Tag

A workflow that says issues-helper@v2.2.1 trusts whatever commit that tag points to today. A workflow that pins a commit hash trusts one specific piece of code. The first is how most of the ecosystem is written, because it is how the documentation shows it. A disabled repository protects tag-pinned users only while it stays disabled, and this file records what happens when the platform’s only control is a switch that somebody flipped back.

The Question GitHub Has Not Answered

Why the repositories were re-enabled, whether by an appeal process or an error, and why the poisoned tags were not removed before restoration, GitHub has not said in public. The corpus filed at 22-0412 the platform’s own account of stolen OAuth tokens four years earlier. Here the platform was not breached. It restored a known-malicious artefact to a registry that thousands of pipelines pull from automatically, and the remediation advice, rotate every secret available to any workflow that ran between 16 and 25 September, is the cost of that decision.

How we reported this

Compiled from Socket’s analysis and contemporaneous reporting, listed below. The re-enablement window and dependent count are Socket’s; the payload description is from Socket and BleepingComputer. GitHub had made no public statement in the material reviewed. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-HuludSocket
  2. GitHub Actions re-enabled with Mini Shai-Hulud payload still activeBleepingComputer
  3. Compromised GitHub Actions Came Back Online and Resumed ExecutingThe Hacker News
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary