Threats · InfosecFeed Brief

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Threats

What you need to know

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]

Source transparency

This is an InfosecFeed curated brief based on reporting from BleepingComputer. InfosecFeed does not claim ownership of the original reporting.

Read the original report at BleepingComputer ↗