$ techbeacon▋
Threats

Maintainer Restores Compromised GitHub Actions, Malicious Payload Still Live

Maintainer Restores Compromised GitHub Actions, Malicious Payload Still Live

Two third‑party GitHub Actions that had been hijacked in the Mini Shai‑Hulud supply‑chain attack were re‑enabled by their maintainer, leaving the malicious code reachable for more than a week after the initial breach was reported.

The Mini Shai‑Hulud campaign, first identified by security researchers earlier this year, targets reusable workflow components on GitHub by injecting a hidden script that can exfiltrate credentials and execute arbitrary commands on downstream projects. The attackers repurpose legitimate actions, replace their source URLs, and then distribute the tainted versions through the public marketplace.

According to the latest findings, the two affected actions were taken offline shortly after the compromise was disclosed. However, the maintainer later restored the actions to the marketplace without removing the altered references. The re‑enabled versions continued to point at the attacker‑controlled repository, allowing any workflow that pulls the actions to fetch the malicious payload again. The window of exposure spanned at least eight days, during which developers who automatically updated their pipelines could have inadvertently re‑introduced the threat.

Security experts warn that this episode underscores the fragility of the software supply chain, especially when open‑source components are trusted without verification. GitHub has reiterated its commitment to scanning and flagging compromised actions, but the platform relies heavily on maintainers to act promptly when issues arise. The incident has sparked renewed calls for stricter provenance checks, such as signed commits and automated integrity verification for third‑party actions.

Going forward, the maintainer has been urged to remove the malicious references and to audit all versions of the affected actions. Organizations are advised to review their CI/CD pipelines, pin specific action versions, and employ tools that detect unexpected changes in dependencies. The broader community continues to monitor the Mini Shai‑Hulud campaign, anticipating that further variants may emerge as attackers adapt to evolving defenses.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related