As reported by The Hacker News, two GitHub Actions from the actions-cool organization—issues-helper and maintain-one-comment—were disabled for a second time after resurfacing on September 16, 2026, with their malicious release tags still intact from the May 2026 Mini Shai-Hulud compromise. This is not merely a re-infection story; it is a case study in how supply chain persistence outlasts incident response when remediation is incomplete.

Threat Alert: As reported by The Hacker News, two GitHub Actions from the actions-cool organization—issues-helper and maintain-one-comment—were disabled for a second time after resurfacing on September 16, 2026, with their malicious release tags still intact from the May 2026 Mini Shai-Hulud compromise.

Why This Incident Matters More Than It Appears

The critical insight here is not that the repositories came back online—platform-level actions like that happen for operational reasons. The real failure is that malicious tags were never scrubbed before the repos became accessible again. Any CI/CD workflow referencing these actions by version tag (e.g., @v3) automatically pulled and executed the credential-harvesting payload on its next scheduled run. No new exploit, no new infrastructure, no attacker action required. The supply chain bomb was still armed, just waiting for a trigger.

This exposes a fundamental gap in how platforms handle compromised package repositories: disabling access is containment, not remediation. Without tag-level cleanup, re-enablement equals re-weaponization.

Who Is Affected

Why This Incident Matters More Than It Appears
Open-source maintainers using actions-cool Actions for issue and comment automation—these are popular utilities with broad adoption across thousands of repositories
Organizations with CI/CD pipelines that reference these Actions by mutable version tags rather than pinned commit SHAs
Downstream software consumers who depend on projects whose build pipelines may have been compromised, potentially injecting malicious artifacts into published packages
The broader npm ecosystem, given the confirmed overlap with the @antv ecosystem compromise through the shared exfiltration domain t.m-kosche[.]com

The Pinning Problem Is Still Unsolved at Scale

The article notes that workflows pinning to a full commit SHA from before May 18 were not impacted. This is the textbook recommendation—yet adoption remains stubbornly low. Mutable tags are the default ergonomic choice for most developers, and GitHub's UI actively encourages @v1-style references. Until pinning-by-SHA becomes a platform-enforced default or a hard policy gate in enterprise environments, this attack pattern will repeat across every package ecosystem that supports mutable references.

Shield53 Recommendations

Immediate Actions

  • Audit all workflow files across your GitHub organizations for references to actions-cool/issues-helper and actions-cool/maintain-one-comment. Search both .github/workflows/ and any composite action repositories.
  • Rotate all secrets that were accessible to any CI/CD pipeline using these Actions between May 18 and September 25, 2026. Assume credentials were exfiltrated—treat this as a confirmed breach, not a potential one.
  • Block the exfiltration domain t.m-kosche[.]com at egress proxies, DNS resolvers, and firewall layers. Review logs for historical connections.
  • Replace or remove the compromised Actions from all workflows. If the functionality is essential, fork a known-clean commit, audit the code, and self-host or pin to a verified SHA.

Strategic Hardening

  • Enforce commit-SHA pinning organization-wide using policy-as-code tools like GitHub's Organization Rulesets or third-party gatekeepers. Reject any workflow PR that references an Action by mutable tag.
  • Implement OIDC-based short-lived credentials instead of long-lived tokens in CI/CD pipelines. If credentials are exfiltrated, they should already be expired by the time they reach the attacker.
  • Deploy runtime monitoring on CI/CD runners to detect unexpected outbound network connections—especially to newly registered or low-reputation domains.
  • Maintain an SBOM for your CI/CD supply chain, not just your application dependencies. Know every Action, runner image, and tool your pipelines execute.

The Mini Shai-Hulud cluster has now demonstrated persistence across both npm and GitHub Actions using shared infrastructure. This is a coordinated supply chain operation, not a one-off compromise. Defenders should expect additional ecosystems to be targeted and treat CI/CD pipeline security with the same rigor applied to production infrastructure.