• Sources: primary, discussion
  • Summary: Socket reports that two GitHub Actions repositories disabled in May over a compromise had access restored, which reactivated a months-old payload with no new attacker action. The dependency graph lists about 15,000 dependents for issues-helper alone. Socket's update dated 2026-09-25 states that actions-cool/issues-helper and actions-cool/maintain-one-comment have been disabled on GitHub again, so workflows referencing them now fail at job setup instead of running the payload.
  • Why it matters: A platform decision rather than an attack re-armed a supply-chain compromise for a window running 2026-09-16 to 2026-09-25, so a workflow that referenced either action by tag and ran a job inside that window executed the payload with the job token and needs every secret it could reach rotated, while a workflow with no job run in the window did not execute it.
  • Follow-up: Track whether the malicious tags are removed, and whether a fuller dependent count is published.

send feedback on this story