Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
ID: c70a2201-e687-588b-a5d8-d77ed699e1b9
STIX ID: report--c70a2201-e687-588b-a5d8-d77ed699e1b9
Feed Name: The Hacker News
Researchers disclosed a large-scale campaign that turned compromised GitHub repositories and Packagist packages into distributed attack infrastructure: malicious GitHub Actions workflows launched GitHub-hosted runners that downloaded a Linux payload from 43.228.157.68 to scan for and exploit CVE-2026-41940 in cPanel/WHM, harvest credentials and secrets, and exfiltrate data; related activity (Operation Muck and Load) uses ~200 repositories to deliver Windows malware and credential-stealing payloads, and investigators have identified thousands of malicious workflow files and unique identifiers tied to the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
