[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:re-enabled-github-actions-expose-thousands-of-repositories-to-mini-shai-hulud-muhzkhrz":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":16,"article_ids":17,"ioc_summary":19,"source_urls":20,"status":22,"expires_at":23,"created_at":24,"updated_at":25,"articles":26},"1d67da9d-852d-42dc-9b1d-9e1c2b57f3a7","Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud","re-enabled-github-actions-expose-thousands-of-repositories-to-mini-shai-hulud-muhzkhrz","Two GitHub Actions (issues-helper and maintain-one-comment) were re-enabled on September 16, 2026 with malicious code still present, resuming execution across approximately 15,000 dependent repositories. Any workflow referencing these actions by tag is now executing the Mini Shai-Hulud malware payload. This represents active supply chain compromise affecting a significant portion of the GitHub ecosystem.","critical","advisory",[],[13,14,15],"GitHub Actions","issues-helper","maintain-one-comment","Immediately audit your organization's GitHub workflows for dependencies on issues-helper and maintain-one-comment actions. Identify affected repositories, revoke any GitHub PATs or secrets that may have been exposed, and review CI\u002FCD logs for suspicious activity dating back to May 2026.",[18],"579eda7d-3072-445c-9f5d-a647b18afc39",null,[21],"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fmini-shai-hulud-actions?utm_medium=feed","active","2026-09-28T06:05:45.245+00:00","2026-09-26T06:05:48.200349+00:00","2026-09-26T06:06:46.427625+00:00",[27],{"id":18,"title":6,"url":21}]