Two third-party GitHub Actions are re-enabled after prior disabling following compromise in the “Mini Shai-Hulud” campaign, and they begin executing again when the repositories become accessible. Multiple sources report that the affected Actions are actions-cool/issues-helper and actions-cool/maintain-one-comment.

Bleeping Computer reports that the Actions are re-enabled by their maintainer and that, during the time they are accessible, they continue to point to malicious code, indicating the payload remains active. The Hacker News describes the same Actions becoming available again after previously being disabled for a second time, mentioning that the repositories reappear and execution resumes.

Across outlets, the core point is that the Actions are not merely restored to normal functionality; they still reference the compromised implementation associated with the Mini Shai-Hulud activity. Both accounts focus on the timeline of disablement and re-access, while they differ in emphasis: Bleeping Computer highlights that they remain live for more than a week with malicious code still in place, while The Hacker News stresses the reappearance and resumption of malware execution after access returns.