GitHub briefly restored access to the compromised actions-cool/issues-helper and actions-cool/maintain-one-comment repositories, whose release tags still pointed to malicious code inserted during the May 2026 Mini Shai-Hulud supply-chain campaign. Workflows referencing mutable action tags automatically retrieved and ran the payload after reactivation—without a workflow change or new attacker access—potentially affecting roughly 15,000 repositories that depend on issues-helper, especially through scheduled, issue, or pull-request-triggered jobs. GitHub has since disabled the repositories again.
The malware harvested CI/CD secrets and exfiltrated them to attacker-controlled infrastructure. Organizations using either action should remove or replace it, identify workflows that reference mutable tags, and pin any required dependency to a verified clean full commit SHA from before May 18. They should also rotate potentially exposed secrets, review workflow logs and permissions, and audit repository history for unauthorized commits or other signs of follow-on activity.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Workflows using mutable tags such as actions-cool/issues-helper@v2.2.1 resumed downloading and executing the compromised payload without changes to downstream workflow files or new attacker activity. A scheduled Moonofweisheng/wot-design-uni workflow shifted from short setup failures on September 14–15 to a successful nine-minute run on September 16, consistent with the action becoming available again.
GitHub made both actions-cool repositories accessible again, although their release tags continued to resolve to the malicious code introduced in May. The repositories were re-enabled during a window observed on September 16.
GitHub's security team disabled the two compromised action repositories one day after the malicious content was introduced. Dependent workflows could no longer download the actions and failed during job setup before action code executed.
The Mini Shai-Hulud campaign compromised actions-cool/issues-helper and actions-cool/maintain-one-comment, inserting code that harvested CI/CD credentials and exfiltrated them to attacker-controlled infrastructure. The activity was linked to the cluster through overlap with the t.m-kosche[.]com exfiltration domain.
GitHub disabled actions-cool/issues-helper and actions-cool/maintain-one-comment for a second time, citing a terms-of-service violation, after their brief re-enablement. The reason the repositories had become accessible again was not known.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.