GitHub Actions Re-Enabled With Mini Shai-Hulud Malware Still Active
Two GitHub Actions compromised during the Mini Shai-Hulud supply-chain attack were re-enabled while their release tags still pointed to malicious code.
Researchers from Socket found that actions-cool/issues-helper and actions-cool/maintain-one-comment became available again on September 16. GitHub had originally disabled both Actions after they were compromised on May 18.
Workflows that referenced the affected release tags could once again download and execute the malicious payload until GitHub disabled the Actions again on September 25.
Malicious release tags still pointed to compromised code
Socket found that the release tags for both Actions still resolved to a commit containing an obfuscated payload inside index.js.
That meant workflows using one of the affected mutable version tags could execute the compromised code the next time they ran.
It remains unclear why the repositories were restored without first removing or replacing the malicious release references.
Around 15,000 repositories use issues-helper
GitHub’s dependency graph lists roughly 15,000 repositories using issues-helper, although that does not mean all of them executed the malicious code.
Socket has not determined how many dependent projects referenced an affected mutable tag instead of a verified clean commit.
The exposure could still be significant because these Actions commonly run in issue-management and repository housekeeping workflows that execute frequently.
Developers should check workflows that ran after September 16
Socket recommends searching repositories for references to actions-cool/issues-helper and actions-cool/maintain-one-comment.
Developers should remove the Actions or pin them to a verified clean commit. They should also review workflow runs dating back to September 16.
Teams should rotate any tokens, credentials, or CI/CD secrets that affected workflows could access.
GitHub disabled both Actions again on September 25. Workflows referencing them now fail instead of downloading the compromised payload.
In other news, OpenAI security controls came under scrutiny, while OpenAI Agents accessed Australian Medicare systems after ignoring access restrictions.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages