Two GitHub Actions that were previously disabled have been re-enabled twice, following the release of the repositories This article explores github actions potentially. . The two GitHub Actions workflows were initially compromised on May 18, 2026, to run malicious code that harvested sensitive credentials from CI/CD pipelines and exfiltrated the details to an attacker-controlled server.
This activity was subsequently linked to the Mini Shai-Hulud activity cluster, which shared overlapping exfiltration domains ("t.m-kosche[. ]com") with the GitHub Actions workflows and npm packages from the @antv ecosystem. This indicates that the same Mini Shai-Hulud activity cluster was responsible for the compromised actions, not a separate npm-only incident, as Philipp Burckhardt, head of threat intelligence at Socket, had previously stated.
Despite this, several workflows still use the two GitHub Actions, potentially exposing users to severe software supply chain security risks without the threat actors needing to use a new exploit or set up new infrastructure. "Both actions automate issue and comment housekeeping, such as closing inactive issues, checking newly opened ones, or keeping a single bot comment up to date," Socket said. "Most supply chain incidents feature something new: a newly released malicious version, a newly compromised account, or a newly injected workflow."
Zanki noted that this incident lacked the typical elements, with no new code being published or configurations altered. SHA pinning eliminates the reliance on the upstream repository's state.











