# GitHub disables two compromised Actions after renewed exposure

_Published Saturday, September 26, 2026 at 11:07 AM EDT · Security · Latest · Tier 2 — Notable_

![GitHub disables two compromised Actions after renewed exposure — Primary](https://www.bleepstatic.com/content/hl-images/2026/05/05/Hackerbox.jpg)

Two compromised third-party GitHub Actions were disabled again on September 25 after their release tags had pointed to malicious code for more than a week, BleepingComputer reported, citing Socket researchers. The actions became accessible on September 16 without their old payload being removed, so workflows using those tags could download and run it. The malware targets developer tokens, credentials and automation secrets.

GitHub's dependency graph lists about 15,000 repositories depending on one of the actions, but that figure does not show how many ran a compromised tag. Workflows referencing the disabled actions now fail instead of running the payload.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/)

---
Canonical: https://techandbusiness.org/newswire/KIg2QLmMTAzhUSuQduVecB
Published: 2026-09-26T15:07:23.202Z
Story chronology: 2026-09-25T00:00:00.000Z
Retrieved: 2026-09-26T16:53:47.532Z
Publisher: Tech & Business (techandbusiness.org)
