logo

Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign

ID: 1795a863-06dd-51cc-af31-d3a7cd47d200

STIX ID: report--1795a863-06dd-51cc-af31-d3a7cd47d200

Feed Name: Socket Blog

Threat Score
85/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

Author: Kirill Boychenko

...
...

Malicious GitHub Actions workflows pushed to repositories tied to the Packagist maintainer dinushchathurya converted compromised repositories into distributed scanning and exploitation infrastructure: ephemeral GitHub-hosted Ubuntu runners downloaded architecture-specific payloads from 43.228.157.68 to scan internet-facing cPanel/WHM systems, attempt exploitation of CVE-2026-41940, and exfiltrate server-side credentials and secrets. The report details IOCs (C2 IP and ports, payload delivery and exfiltration endpoints, DNSHook hostname, payload SHA-256), describes resilient heartbeat and chunked exfiltration mechanisms, estimates campaign scale in the thousands of workflow files, and recommends disabling suspicious workflows, rotating credentials, restricting CI permissions, removing affected Packagist development versions, and patching cPanel/WHM.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.