GitHub Actions re-enabled with Mini Shai-Hulud payload still active
BLUF
Maintainer error kept malicious GitHub Actions active, extending the supply chain attack window.
NEWS
Two third-party GitHub Actions linked to the Mini Shai-Hulud campaign were re-enabled despite retaining malicious payloads. These actions remained accessible for more than a week, continuing to expose downstream projects to compromise.
Why I Care
This incident underscores the risk of trusting maintainer decisions in supply chain security without independent verification. Organizations relying on these Actions face potential code execution and credential theft within their CI/CD pipelines.
Next Steps
Immediately audit all third-party GitHub Actions for known compromised packages and disable suspicious dependencies. Pin versions to verified commits instead of tags and implement automated scanning for malicious code before re-enabling any action.
Source: BleepingComputer ·