Re-Enabled GitHub Actions Repos Trigger Malicious Code Re-Execution in CI Pipelines
Two GitHub Actions repositories — actions-cool/issues-helper and actions-cool/maintain-one-comment — were re-enabled on September 16, 2026, weeks after being disabled following a supply chain attack discovered in May 2026. The repositories were restored while still carrying malicious tags from the original compromise, meaning no new attacker activity was needed to resume the threat. Security firm Socket confirmed through execution logs that workflows referencing issues-helper re-ran the malicious payload upon the repositories being restored. GitHub's dependency graph shows approximately 15,000 repositories relied on issues-helper, though this figure reflects potential exposure rather than confirmed cases of code execution or data theft. GitHub disabled both repositories again on September 25, 2026, after the renewed risk was identified.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in