Exploitation of GitHub Actions Runners for cPanel/WHM Server Attacks via Compromised Repositories
Attackers exploited compromised GitHub repositories to deploy malicious workflows that leverage GitHub Actions runners for scanning and exploiting cPanel/WHM servers via CVE-2026-41940, stealing credentials and sensitive data. The campaign uses distributed infrastructure through GitHub-hosted runners to bypass traditional package-based attack vectors.
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances.
The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13,
*** END OF TRANSMISSION ***