AUTO-UPDATED

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Compromised GitHub repositories are being used to launch automated attacks against cPanel and WHM servers by exploiting a critical authentication bypass vulnerability identified as CVE-2026-41940.

Key Points

  • Attackers compromised 10 Packagist packages belonging to developer dinushchathurya between July 12 and 13, 2026.
  • Malicious GitHub Actions workflows were injected into repositories to trigger scanning and exploitation payloads.
  • The campaign uses GitHub-hosted runners to target servers vulnerable to CVE-2026-41940, bypassing authentication to harvest sensitive credentials and cloud keys.
  • Researchers identified approximately 6,100 malicious workflow files linked to the campaign, indicating a large-scale, automated infrastructure.
  • Stolen data includes AWS credentials, Stripe keys, SSH material, and various API tokens used for follow-on monetization or system compromise.

Why it Matters

This campaign demonstrates a sophisticated shift where attackers abuse legitimate CI/CD infrastructure to conduct large-scale, automated server exploitation rather than targeting individual end-users. Organizations must audit their GitHub Actions workflows and prioritize patching cPanel and WHM instances to mitigate the risk of credential theft and unauthorized remote access.
Internet Published by info@thehackernews.com (The Hacker News)
Read original