The Dead Wolves Came Back. Of Course They Did.
Oh good. My coffee's cold, I've got 47 tickets in the queue, and apparently the fleas we thought we killed in May are back. Living their best life. Executing code. Having a grand time.
Let me explain this disaster to the flock.
Back in May 2026, two GitHub Actions got compromised as part of the Mini Shai-Hulud campaign. The affected repos were actions-cool/issues-helper and actions-cool/maintain-one-comment. Cute names. Harmless vibes. Full of parasites.
GitHub disabled them. We all moved on. Some of us even slept for a few hours.
Then, last week, the repositories quietly came back online. No fanfare. No announcement. Just, hey, we're accessible again, please pull us into your CI/CD pipelines, we definitely don't have fleas anymore. The wolves apparently just walked back through a hole in the fence that nobody bothered to fill.
And yes, the malicious code resumed executing. Because of course it did.
GitHub has since disabled them again, and visiting either repo now gives you an access denied message. Great. Two disables for the price of one compromise. Very efficient.
Here is what genuinely exhausts me about this: someone, somewhere in the Shepherds' org, probably looked at a dashboard in May, saw "threat remediated," and checked the box. Nobody verified the actual fence line. Nobody confirmed the hole was sealed. They just... assumed.
The Lambs in your pipelines were happily pulling these actions into automated workflows, completely unaware that the grain was fake and the wolf was back in the barn wearing a GitHub badge.
I need to lie down.
Remediation
Look, I'm tired, so I'll keep this brief.
Audit your GitHub Actions dependencies right now. Not tomorrow. Now. If actions-cool/issues-helper or actions-cool/maintain-one-comment appear anywhere in your workflows, yank them out and assume the worst.
Pin your actions to a specific commit hash, not a tag. Tags can be moved. Hashes cannot. This is not optional, this is basic flock hygiene.
Review your CI/CD pipeline logs from the window when the repos were accessible again. If you pulled them during that period, you potentially ran compromised code. Treat it accordingly and start shearing everything downstream.
Set up alerts for dependency changes in your automated workflows. If something that was disabled suddenly becomes accessible again, you want to know about it before your pipeline does.
And maybe, just maybe, verify your remediations actually remediated something before closing the ticket.
Closing tickets without verifying fixes is how we end up here, and "here" is where I live now apparently.
Still haven't slept, send help.
Original Report: https://thehackernews.com/2026/09/compromised-github-actions-came-back.html