Compromised GitHub Actions Reenabled, Risk Renewed
🔒 Two GitHub Actions that were compromised in May 2026 and disabled by GitHub were re-enabled on September 16, 2026, restoring access to repositories containing unremediated malicious release tags. Socket researcher Karlo Zanki warned that workflows referencing the affected tags resumed downloading and executing the May 18 payload, which harvests CI/CD secrets and exfiltrates them. Developers are urged to pin to pre‑compromise SHAs, rotate secrets, audit workflow history, and remove or replace the affected actions.
