Compromised GitHub Actions returned online with malware payload intact

Two third-party GitHub Actions that were compromised in May's Mini Shai-Hulud supply-chain campaign were re-enabled by their maintainer and stayed accessible for more than a week while still pointing to malicious code. Socket researchers found the release tags resolved to an obfuscated payload, so workflows referencing those actions downloaded and ran the malware from September 16 through September 25. GitHub disabled the actions again on September 25.
... No extra. Need maybe no bullets. Plain text. Check EXPANDED total under 120. Let's final. Ensure no source phrasing copied. "Mini Shai-Hulud" okay. "323 npm packages and 639 versions" factual. "developer tokens, credentials, and CI/CD secrets" source says tokens, credentials, and CI/CD secrets. Could be okay but maybe original? We can say "access keys, login credentials, and pipeline secrets" but CI/CD secrets is term. Fine. "release tags" technical. "obfuscated index.js payload" source. Maybe okay. Need entirely original wording, never copying source phrasing. We can rephrase: "their version labels still pointed to a hidden payload in index.js". Good. Let's rewrite. EXPANDED: Mini Shai-Hulud, a May supply-chain campaign, infected 323 npm packages and 639 versions, targeting access keys, login credentials, and pipeline secrets. The two GitHub Actions, issues-helper and maintain-one-comment, were removed after a May 18 compromise. Socket says they returned September 16 with versio