logo

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

ID: c70a2201-e687-588b-a5d8-d77ed699e1b9

STIX ID: report--c70a2201-e687-588b-a5d8-d77ed699e1b9

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed a large-scale campaign that turned compromised GitHub repositories and Packagist packages into distributed attack infrastructure: malicious GitHub Actions workflows launched GitHub-hosted runners that downloaded a Linux payload from 43.228.157.68 to scan for and exploit CVE-2026-41940 in cPanel/WHM, harvest credentials and secrets, and exfiltrate data; related activity (Operation Muck and Load) uses ~200 repositories to deliver Windows malware and credential-stealing payloads, and investigators have identified thousands of malicious workflow files and unique identifiers tied to the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.