Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign
ID: 1795a863-06dd-51cc-af31-d3a7cd47d200
STIX ID: report--1795a863-06dd-51cc-af31-d3a7cd47d200
Feed Name: Socket Blog
Malicious GitHub Actions workflows pushed to repositories tied to the Packagist maintainer dinushchathurya converted compromised repositories into distributed scanning and exploitation infrastructure: ephemeral GitHub-hosted Ubuntu runners downloaded architecture-specific payloads from 43.228.157.68 to scan internet-facing cPanel/WHM systems, attempt exploitation of CVE-2026-41940, and exfiltrate server-side credentials and secrets. The report details IOCs (C2 IP and ports, payload delivery and exfiltration endpoints, DNSHook hostname, payload SHA-256), describes resilient heartbeat and chunked exfiltration mechanisms, estimates campaign scale in the thousands of workflow files, and recommends disabling suspicious workflows, rotating credentials, restricting CI permissions, removing affected Packagist development versions, and patching cPanel/WHM.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
