Interestana
Home/News/Compromised GitHub Actions Resumed Executing Malware
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Compromised GitHub Actions Resumed Executing Malware

Compromised GitHub Actions Resumed Executing Malware

Two GitHub Actions, specifically actions-cool/issues-helper and actions-cool/maintain-one-comment, were found to have been re-enabled and resumed executing malware, months after their initial compromise. These repositories, part of the actions-cool organization, were first compromised during the May 2026 Mini Shai-Hulud campaign. The campaign involved the deployment of malware, and the subsequent compromise of these GitHub Actions allowed for the continued execution of malicious code. The repositories were initially disabled following the discovery of the compromise, but they have since been made accessible again, leading to the resumption of their malicious activities. When accessing the repositories now, a message indicates that "Access to this repository has been restricted." This indicates a security measure has been put in place, but the underlying issue of the repositories being compromised and subsequently re-enabled suggests a persistent threat. The Mini Shai-Hulud campaign, which led to the initial compromise, was characterized by the deployment of malware. The specific nature of the malware executed by these actions-cool repositories has not been detailed in the provided information, but their re-emergence indicates a significant security lapse. GitHub Actions are a continuous integration and continuous delivery (CI/CD) platform that allows developers to automate software workflows. Compromising such a platform can have far-reaching implications, as it can be used to inject malicious code into legitimate software development pipelines, potentially affecting a wide range of users and systems. The fact that these actions were re-enabled, even with restricted access, raises questions about the security protocols and monitoring mechanisms in place to prevent such reoccurrences. The timeline of events suggests that the compromise occurred sometime in May 2026, and the repositories were disabled thereafter. Their recent re-emergence indicates a period of vulnerability or a failure in the remediation process. The actions-cool organization appears to be a third-party provider of GitHub Actions, meaning that developers integrating these actions into their workflows would be indirectly exposed to the compromise. The implications of this incident extend to the trust placed in third-party tools within the software development ecosystem. The restricted access message suggests that while the repositories are technically accessible, their functionality is likely limited or under scrutiny. However, the core concern remains that the compromised actions were capable of executing malware, and their re-activation poses a renewed risk. Further investigation into the specific vulnerabilities exploited and the extent of the malware's impact would be crucial for understanding the full scope of this security incident. The incident highlights the ongoing challenges in securing CI/CD pipelines against sophisticated threat actors who can exploit trusted tools and platforms.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next