Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-26 · updated: 2026-09-26 · tags: [incident, global] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: true

Two GitHub Actions — actions-cool/issues-helper and actions-cool/maintain-one-comment — were compromised on 18 May 2026 to harvest credentials from CI/CD pipelines that ran them and exfiltrate them to an attacker server, then made inaccessible. On 16 September both repositories became accessible again, at some point between 11:09 and 18:16 GMT+2, and because their release tags still pointed at the malicious content introduced on 18 May, any workflow referencing either action by a version tag resumed downloading and executing the payload on its next run. GitHub disabled the repositories a second time; the reason for the re-enablement is not known. Socket linked the campaign to the Mini Shai-Hulud cluster through the exfiltration domain t.m-kosche[.]com, shared with the compromised @antv npm packages. Both actions automate routine issue and comment housekeeping and their workflows typically run on a daily schedule, so exposure did not require a new exploit or new infrastructure — only the repository becoming downloadable again.

Attribute Detail
Sector Global (Macro)
Date 2026-09-26
Source The Hacker News
Reliability Tier 2