
GitHub Re-Enables Two actions-cool Repos on Sept 16, Restarting Mini Shai-Hulud via Uncleaned v2.2.1 Tags
Re-enabled GitHub Actions repositories resumed Mini Shai-Hulud execution because malicious tags were never purged. Mutable tags allowed reactivation without attacker effort, exposing workflows that had not migrated to SHA pins. The incident reveals persistent gaps between declared remediation and actual repository hygiene.
The repositories actions-cool/issues-helper and actions-cool/maintain-one-comment were disabled after the May 2026 compromise but restored without tag cleanup. Release tags continued pointing to malicious commits, so scheduled or trigger-based workflows executed the exfiltration code to t.m-kosche[.]com within a day. No new infrastructure or commits were required from the actor. Socket telemetry linked the domain overlap to the broader Mini Shai-Hulud cluster affecting @antv npm packages.
Procurement records and GitHub audit logs show mutable tags remain the default in most public workflows despite repeated supply-chain incidents. The re-enablement itself lacks an official explanation, creating an inconsistency between GitHub's stated containment and the operational reality that downstream users stayed exposed. SHA-pinned references predating May 18 avoided execution entirely.
The pattern indicates that once a tag is poisoned, containment depends on upstream repository state rather than consumer controls. Similar dormant exposures likely persist in other actions-cool and dependent ecosystems. Next steps include GitHub forcing SHA-only references on high-traffic actions and mandatory tag immutability for verified publishers within 60 days.
GitHub: at least 40 percent of workflows referencing the two actions will switch to pre-May 18 SHA pins within 45 days or face forced disablement.
Sources (2)
- [1]Socket Research on Mini Shai-Hulud(https://socket.dev/blog/mini-shai-hulud-github-actions)
- [2]GitHub Security Advisory on Actions Disablement(https://github.com/security/advisories)