Published September 24, 2026 · Added September 26, 2026

Mini Shai-Hulud Worm Is Still Infecting GitHub Repositories

SafeDep reports that the Mini Shai-Hulud worm from May 2026 is still infecting new GitHub repositories because the attacker's hijacked tags on the actions-cool/issues-helper GitHub Action were never restored. Six repositories received hook files between September 20 and 24, each infected less than six minutes after an issue-bot workflow ran, and the payload is byte-identical to the May build: it reads the GITHUB_TOKEN from runner memory, commits Claude Code and VS Code hooks into the repository, and runs the malware on any developer who pulls the change and opens the project locally, while the action step itself still appears to succeed.

SafeDep reports that the Mini Shai-Hulud worm from May 2026 is still infecting new GitHub repositories because the attacker’s hijacked tags on the actions-cool/issues-helper GitHub Action were never restored. Six repositories received hook files between September 20 and 24, each infected less than six minutes after an issue-bot workflow ran, and the payload is byte-identical to the May build: it reads the GITHUB_TOKEN from runner memory, commits Claude Code and VS Code hooks into the repository, and runs the malware on any developer who pulls the change and opens the project locally, while the action step itself still appears to succeed.

Read the original story.

Source: Safedep