INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
GitHub Actions Resumed Executing Shai-Hulud Malware After Compromise
| 2026-09-25 14:44 LOW HIGH MALWARE & BOTNETS
Executive Summary
AI-generated
On September 16, 2026, two GitHub Actions repositories became accessible again after being compromised months earlier during the May 2026 Mini Shai-Hulud campaign. The affected entities are approximately unknown in number and include Visiting either of the repositories now shows a message from GitHub Staff due to a violation of their terms of service. The attack works by utilizing overlaps in exfiltration domains ("t.m-kosche[.]com") used in the compromised workflows and npm packages from the @antv ecosystem, linking it to the Mini Shai-Hulud activity cluster. As of now, the malicious code remains active within the affected repositories, posing severe software supply chain security risks without requiring new exploits or infrastructure setup.
Technical Mitigations AI-generated
• Pin affected GitHub Actions to a known-clean SHA that predates May 18, 2026.
• Remove actions and treat "actions-cool/[email protected]" as affected.
• Rotate all exposed secrets.
• Review workflow run history for newly successful runs after September 16, 2026.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
t•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-HuludMini Shai-HuludMini Shai-Hulud
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
March 2026
Threat actors resumed executing Mini Shai-Hulud malware through compromised GitHub Actions in March 2026.
May 2026
Mini Shai-Hulud malware was previously compromised in May 2026 and its associated GitHub Actions repositories became accessible again on September 25, 2026.
Click on any entity below to view its context and source!
malware
Mini Shai-Hulud
Ravie Lakshmanan
Sep 25, 2026
Malware / Supply Chain Attack
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the
May 2026 Mini Shai-Hulud campaign
.
tactic
T1588.001 - Malware
Ravie Lakshmanan
Sep 25, 2026
Malware / Supply Chain Attack
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the
May 2026 Mini Shai-Hulud campaign
.
organisation
GitHub Actions
Ravie Lakshmanan
Sep 25, 2026
Malware / Supply Chain Attack
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the
May 2026 Mini Shai-Hulud campaign
.
general_metric
25 Sep
Ravie Lakshmanan
Sep 25, 2026
Malware / Supply Chain Attack
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the
May 2026 Mini Shai-Hulud campaign
.
general_metric
2026
Ravie Lakshmanan
Sep 25, 2026
Malware / Supply Chain Attack
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the
May 2026 Mini Shai-Hulud campaign
.
organisation
GitHub
The affected GitHub Actions are listed below -
Visiting either of the repositories now shows the message: "Access to this repository has been disabled by GitHub Staff due to a violation of GitHub's terms of service.
May 18, 2026
Two GitHub Actions workflows were compromised on May 18, 2026, to run malicious code that harvested sensitive credentials and exfiltrated details to an attacker-controlled server linked to the Mini Shai-Hulud activity cluster.
Click on any entity below to view its context and source!
organisation
CI
"
The two GitHub Actions workflows were originally compromised on May 18, 2026, to run malicious code that harvested sensitive credentials from CI/CD pipelines that ran them and exfiltrated the details to an attacker-controlled server.
organisation
SHA
The issue does not impact workflows that pin either action to the full commit SHA of a version from before May 18, 2026.
organisation
Socket
"That points to the same Mini Shai-Hulud activity cluster, not a separate npm-only incident," Philipp Burckhardt, head of threat intelligence at Socket, told The Hacker News at the time.
organisation
The Hacker News
"That points to the same Mini Shai-Hulud activity cluster, not a separate npm-only incident," Philipp Burckhardt, head of threat intelligence at Socket, told The Hacker News at the time.
organisation
Rotate
Rotate all exposed secrets.
May 18
Threat actors introduced malicious content on GitHub Actions that was later referenced by workflow versions, causing the compromised workflows to resume executing Mini Shai-Hulud malware.
September 2026
Threat actors used compromised GitHub Actions to resume executing the Mini Shai-Hulud malware.
September 16, 2026
The compromised GitHub Actions repositories became accessible again on September 16, 2026.
Sep 16, 2026
Threat actors successfully regained control of the compromised GitHub Actions, which resumed executing the Mini Shai-Hulud malware.
2026/09/18
Mini Shai-Hulud malware was executed by compromised GitHub Actions repositories that became accessible again on September 25, 2026.
Click on any entity below to view its context and source!
malware
Mini Shai-Hulud
Ravie Lakshmanan
Sep 25, 2026
Malware / Supply Chain Attack
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the
May 2026 Mini Shai-Hulud campaign
.
tactic
T1588.001 - Malware
Ravie Lakshmanan
Sep 25, 2026
Malware / Supply Chain Attack
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the
May 2026 Mini Shai-Hulud campaign
.
organisation
GitHub Actions
Ravie Lakshmanan
Sep 25, 2026
Malware / Supply Chain Attack
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the
May 2026 Mini Shai-Hulud campaign
.
general_metric
25 Sep
Ravie Lakshmanan
Sep 25, 2026
Malware / Supply Chain Attack
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the
May 2026 Mini Shai-Hulud campaign
.
general_metric
2026
Ravie Lakshmanan
Sep 25, 2026
Malware / Supply Chain Attack
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the
May 2026 Mini Shai-Hulud campaign
.
Sep 25, 2026
Threat actors successfully regained control of the compromised GitHub Actions, which then resumed executing the Mini Shai-Hulud malware.
2026/09/25
An attacker hijacked an active AI coding-assistant session at a software-as-a-service provider and used it to install an infostealer through a poisoned PyPI package.
Click on any entity below to view its context and source!
organisation
CI
In August, a
Keyv-linked npm worm
poisoned hundreds of packages and planted hooks for Claude Code and Visual Studio Code, while a later analysis found a Shai-Hulud variant scanning
469 locations for credentials
across developer systems, CI/CD tools, cloud configurations, and AI tool files.
infrastructure
Visual Studio Code
In August, a
Keyv-linked npm worm
poisoned hundreds of packages and planted hooks for Claude Code and Visual Studio Code, while a later analysis found a Shai-Hulud variant scanning
469 locations for credentials
across developer systems, CI/CD tools, cloud configurations, and AI tool files.
organisation
Attacker Hijacks AI Coding
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories.
organisation
PyPI
How the Attack Unfolded
After the recommendation was accepted, the attacker used the developer's active session to install an infostealer through a poisoned PyPI package.
organisation
Mandiant
Mandiant had already documented attackers using AI in real attacks.
organisation
Keep
Keep raw API keys, long-lived OAuth tokens, and other secrets out of direct reach of extensions.
organisation
API
Keep raw API keys, long-lived OAuth tokens, and other secrets out of direct reach of extensions.
Tactical Metrics
Metrics
infrastructure
Visual Studio Code
Affected Product
Click for context!
In August, a
Keyv-linked npm worm
poisoned hundreds of packages and planted hooks for Claude Code and Visual Studio Code, while a later analysis found a Shai-Hulud variant scanning
469 locations for credentials
across developer systems, CI/CD tools, cloud configurations, and AI tool files.
Intelligence Sources
The Hacker News
2026-09-16
The Hacker News
2026-09-25
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T12:08
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
GitHub Actions
entity
11x
timeline
Temporal Reference
Sep 25, 2026
date
3x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
2x
malware
Malware Payload
Mini Shai-Hulud
tool
2x
general metric
Sep
25
sep
Contextual Telemetry
Context Block
5 METRICS
tactic
Cyber Operation Type
Exfiltration
tactic
general metric
2,026
infrastructure
Affected Product
Visual Studio Code
software
general metric
Locations
469
locations
general metric
Repositories
100
repositories
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.