Two compromised GitHub Actions reportedly re-enabled while still pointing to malicious code
BleepingComputer reports that the third-party actions had been compromised in a Mini Shai-Hulud campaign and remained accessible for more than a week after being re-enabled.
TLDR
Two third-party GitHub Actions compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer, BleepingComputer reports. The actions still pointed to malicious code and remained accessible for more than a week.
Combined views
5K
1 Source, first seen 6h ago
8 likes