<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/re-enabled-github-actions-expose-thousands-of-repositories-to-mini-shai-hulud-gbszftbdt" -->

---
title: Re-Enabled GitHub Actions Expose Thousands of...
description: Two GitHub Actions from the actions-cool project, issues-helper and maintain-one-comment, were compromised and disabled in May 2026 during the Mini Shai-Hulud...
canonical: https://daily.dev/posts/re-enabled-github-actions-expose-thousands-of-repositories-to-mini-shai-hulud-gbszftbdt
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud | daily.dev
og:description: Two GitHub Actions from the actions-cool project, issues-helper and maintain-one-comment, were compromised and disabled in May 2026 during the Mini Shai-Hulud...
og:url: https://daily.dev/posts/re-enabled-github-actions-expose-thousands-of-repositories-to-mini-shai-hulud-gbszftbdt
og:image: https://api.daily.dev/og/posts/gBSZFTBDT.png
og:image:alt: Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud

**[Socket](https://daily.dev/sources/socketdev)** · 1 min read · 1 upvotes · 0 comments

## Summary

Two GitHub Actions from the actions-cool project, issues-helper and maintain-one-comment, were compromised and disabled in May 2026 during the Mini Shai-Hulud supply chain attack. On September 16, 2026, both actions became reachable again, but their release tags still point to the original malicious code. Any workflow referencing these actions by version tag rather than a pinned commit SHA is once again executing the malicious payload, putting thousands of downstream repositories at risk.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://socket.dev/blog/mini-shai-hulud-actions>

## Questions this post answers

### Are the issues-helper and maintain-one-comment GitHub Actions safe to use again?

No, they are not safe. Both actions-cool GitHub Actions were compromised and disabled during the May 2026 Mini Shai-Hulud campaign, and although they became reachable again on September 16, 2026, their release tags still point to the original malicious code, so referencing them by tag still runs the malicious payload.

_Teams pinning GitHub Actions dependencies can track supply chain incidents like this one on daily.dev._

### Why is pinning a GitHub Action by commit SHA instead of by tag important for security?

Pinning by commit SHA prevents a compromised or re-enabled action from silently serving malicious code, since a tag can be re-pointed to different content while a commit SHA is immutable. In the Mini Shai-Hulud case, workflows referencing issues-helper or maintain-one-comment by tag started running the malicious payload again once the actions were re-enabled with their old tags intact.

_Developers hardening CI/CD pipelines follow supply chain security guidance like this on daily.dev._

## Similar posts on daily.dev

- [Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised](https://daily.dev/posts/mini-shai-hulud-strikes-again-317-npm-packages-compromised-u2ptexbxr) · Hacker News · 2 upvotes · 0 comments
- [simonecorsi/mawesome GitHub Action has been compromised](https://daily.dev/posts/simonecorsi-mawesome-github-action-has-been-compromised-ckc9svqze) · StepSecurity · 1 upvotes · 0 comments
- [GitHub Actions is the weakest link](https://daily.dev/posts/github-actions-is-the-weakest-link-kx8cbboab) · Andrew Nesbitt · 1 upvotes · 0 comments
- [Is GitHub Actions Putting Your Software at Risk?](https://daily.dev/posts/is-github-actions-putting-your-software-at-risk--a2b2a1jji) · Atomic Spin · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#open-source](https://daily.dev/tags/open-source), [#cicd](https://daily.dev/tags/cicd), [#github-actions](https://daily.dev/tags/github-actions)

[View this post on daily.dev](https://daily.dev/posts/re-enabled-github-actions-expose-thousands-of-repositories-to-mini-shai-hulud-gbszftbdt)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud","url":"https://daily.dev/posts/re-enabled-github-actions-expose-thousands-of-repositories-to-mini-shai-hulud-gbszftbdt","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/re-enabled-github-actions-expose-thousands-of-repositories-to-mini-shai-hulud-gbszftbdt"},"datePublished":"2026-09-24T22:53:15.636Z","dateModified":"2026-09-25T04:00:30.200Z","description":"Two GitHub Actions from the actions-cool project, issues-helper and maintain-one-comment, were compromised and disabled in May 2026 during the Mini Shai-Hulud...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3118351fb5d73038fe139000aecfdead?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3118351fb5d73038fe139000aecfdead?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Socket","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Socket","logo":"https://media.daily.dev/image/upload/s---oEn9czC--/f_auto/v1716187892/logos/socketdev","url":"https://daily.dev/sources/socketdev"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/re-enabled-github-actions-expose-thousands-of-repositories-to-mini-shai-hulud-gbszftbdt","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,open-source,cicd,github-actions","timeRequired":"PT1M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Socket","item":"https://daily.dev/sources/socketdev"},{"@type":"ListItem","position":3,"name":"Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/re-enabled-github-actions-expose-thousands-of-repositories-to-mini-shai-hulud-gbszftbdt#faq","mainEntity":[{"@type":"Question","name":"Are the issues-helper and maintain-one-comment GitHub Actions safe to use again?","acceptedAnswer":{"@type":"Answer","text":"No, they are not safe. Both actions-cool GitHub Actions were compromised and disabled during the May 2026 Mini Shai-Hulud campaign, and although they became reachable again on September 16, 2026, their release tags still point to the original malicious code, so referencing them by tag still runs the malicious payload. Teams pinning GitHub Actions dependencies can track supply chain incidents like this one on daily.dev."}},{"@type":"Question","name":"Why is pinning a GitHub Action by commit SHA instead of by tag important for security?","acceptedAnswer":{"@type":"Answer","text":"Pinning by commit SHA prevents a compromised or re-enabled action from silently serving malicious code, since a tag can be re-pointed to different content while a commit SHA is immutable. In the Mini Shai-Hulud case, workflows referencing issues-helper or maintain-one-comment by tag started running the malicious payload again once the actions were re-enabled with their old tags intact. Developers hardening CI/CD pipelines follow supply chain security guidance like this on daily.dev."}}]}
```

