Bottom line: You can’t control when a compromised repository comes back online, but you can control what your workflows run.
Pin third-party GitHub Actions to a known-clean commit SHA. That would have stopped this malicious code from running in both May and September.