Back to advisories

Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud

Two GitHub Actions (issues-helper and maintain-one-comment) were re-enabled on September 16, 2026 with malicious code still present, resuming execution across approximately 15,000 dependent repositories. Any workflow referencing these actions by tag is now executing the Mini Shai-Hulud malware payload. This represents active supply chain compromise affecting a significant portion of the GitHub ecosystem.

CRITICALAdvisorySep 26, 2026
Action required
Immediately audit your organization's GitHub workflows for dependencies on issues-helper and maintain-one-comment actions. Identify affected repositories, revoke any GitHub PATs or secrets that may have been exposed, and review CI/CD logs for suspicious activity dating back to May 2026.
Affected products
GitHub Actionsissues-helpermaintain-one-comment