
GitHub Actions compromised in May came back online in September — malware payload still active
Two GitHub Actions disabled during the May 2026 Mini Shai-Hulud supply chain attack were silently re-enabled on September 16. Their malicious release tags were never cleaned up, meaning any workflow referencing them ran the credential-stealing payload for over a week before GitHub disabled them again.










