Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Here is a supply-chain failure mode I had not thought about: two actions-cool GitHub Actions compromised on May 18 were disabled, then quietly re-enabled on September 16 with the malicious code still sitting in the repo. Anything pinned to a tag like @v2.2.1 went straight back to harvesting CI credentials, no new attack needed. Pin to a commit SHA from before May 18 and go read your workflow run history.