• Sources: report
  • Summary: Both actions were restored to the marketplace with release tags still resolving to the Mini Shai-Hulud credential-stealing payload, so workflows referencing them by mutable version tag ran that code between 2026-09-16 and 2026-09-25. GitHub disabled both again on 2026-09-25, so workflows referencing them now fail rather than execute the payload. The remaining work is removing the reference or pinning a verified clean commit, reviewing workflow runs since 2026-09-16, and rotating any secret those workflows could reach.
  • Why it matters: GitHub's dependency graph lists about 15,000 repositories depending on issues-helper alone, and each one that referenced a mutable version tag rather than a commit SHA ran attacker-controlled code for those nine days.

send feedback on this story