Skip to main content
CyberReportedMediumDeveloping
5.0

Compromised GitHub Actions re-enabled with malicious payload still active

Two third-party GitHub Actions, previously compromised in the Mini Shai-Hulud campaign, were re-enabled by their maintainer and remained accessible for over a week while still pointing to malicious code. The re-enabling suggests a lapse in remediation or a deliberate act, and the continued availability of the malicious actions poses a supply-chain risk to downstream users.

BleepingComputerabout 21 hours agoengCredibility 20%View source

Score Breakdown

Mosaic Score5.0
Model confidence0.7
Significance0.5
Source credibility0.2
Source

Related signals

8 found