
Re-enabled GitHub Actions Still Point to Malicious Mini Shai-Hulud Payload
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. Users who re-added these actions to their workflows were exposed to execution of malicious code, including potential cryptocurrency mining malware and credential theft, compromising CI/CD security and potentially exposing source code and artifacts.
