# GitHub Actions re-enabled with Mini Shai-Hulud payload still active

DevFeed: [GitHub Actions re-enabled with Mini Shai-Hulud payload still active](<https://devfeed.tech/articles/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active-60341.md>)

Original publisher: [Read original article](<https://www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/>)

Author: Bill Toulas

Published: 2026-09-26T14:19:46Z

Content type: news

Language: en

Sources: [BleepingComputer](<https://devfeed.tech/sources/bleepingcomputer.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Security](<https://devfeed.tech/topics/security.md>), [Reverse Dependencies](<https://devfeed.tech/topics/reverse-dependencies.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [attack](<https://devfeed.tech/tags/attack.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [computer-help](<https://devfeed.tech/tags/computer-help.md>), [computer-security](<https://devfeed.tech/tags/computer-security.md>), [computers](<https://devfeed.tech/tags/computers.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [dependency-graph](<https://devfeed.tech/tags/dependency-graph.md>), [developers](<https://devfeed.tech/tags/developers.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [infosec-computer-security](<https://devfeed.tech/tags/infosec-computer-security.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mac](<https://devfeed.tech/tags/mac.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-removal](<https://devfeed.tech/tags/malware-removal.md>), [mini-shai-hulud](<https://devfeed.tech/tags/mini-shai-hulud.md>), [npm](<https://devfeed.tech/tags/npm.md>), [packages](<https://devfeed.tech/tags/packages.md>), [release](<https://devfeed.tech/tags/release.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [spyware](<https://devfeed.tech/tags/spyware.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-attack](<https://devfeed.tech/tags/supply-chain-attack.md>), [support](<https://devfeed.tech/tags/support.md>), [tech-support](<https://devfeed.tech/tags/tech-support.md>), [technical-support](<https://devfeed.tech/tags/technical-support.md>), [version](<https://devfeed.tech/tags/version.md>), [virus](<https://devfeed.tech/tags/virus.md>), [virus-removal](<https://devfeed.tech/tags/virus-removal.md>), [windows](<https://devfeed.tech/tags/windows.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

## AI overview

Two compromised third-party GitHub Actions were re-enabled with malicious release tags still pointing to a payload from the Mini Shai-Hulud supply-chain attack. Workflows using those tags could download and execute the payload until the actions were disabled again on September 25, 2026.

## Source excerpt

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]