
The failure to remove malicious release tags before re-enabling the actions-cool repositories allowed credential-stealing code to resume its automated attack cycle. This resurgence of the Mini Shai-Hulud malware campaign in September 2026 represents a critical oversight in repository management, where convenience and restoration speed were prioritized over comprehensive security sanitization. The tools in question, specifically actions-cool/issues-helper and actions-cool/maintain-one-comment, serve as










