Compromised GitHub repositories are being used to launch automated attacks against cPanel and WHM servers by exploiting a critical authentication bypass vulnerability identified as CVE-2026-41940.
Key Points
- Attackers compromised 10 Packagist packages belonging to developer dinushchathurya between July 12 and 13, 2026.
- Malicious GitHub Actions workflows were injected into repositories to trigger scanning and exploitation payloads.
- The campaign uses GitHub-hosted runners to target servers vulnerable to CVE-2026-41940, bypassing authentication to harvest sensitive credentials and cloud keys.
- Researchers identified approximately 6,100 malicious workflow files linked to the campaign, indicating a large-scale, automated infrastructure.
- Stolen data includes AWS credentials, Stripe keys, SSH material, and various API tokens used for follow-on monetization or system compromise.