Compromised GitHub Actions Reactivate Shai-Hulud Supply-Chain Attacks
Compromised GitHub Actions associated with Mini Shai-Hulud can resume credential theft when workflows are re-enabled, demonstrating persistence through mutable action tags rather than fresh malware deployment. Review workflow history and action references, replace affected actions, pin dependencies to immutable SHAs, and rotate GitHub, cloud, registry, and deployment secrets.
Sources (1)
Updated Oct 3, 2026