Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

    July 26, 2026

    Robinhood Chain’s real-world assets jump fivefold as tokenized stocks start trading in size

    July 26, 2026

    Oral GLP-1 drugs may quiet the brain’s food craving circuit

    July 26, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
    • Robinhood Chain’s real-world assets jump fivefold as tokenized stocks start trading in size
    • Oral GLP-1 drugs may quiet the brain’s food craving circuit
    • Does Quaker instant strawberries and cream oatmeal contain castoreum from beaver butts?
    • One killed and 16 injured after van crashes into crowd at Berlin Pride | Germany
    • Samsung Galaxy Z Fold 8 Ultra vs. Z Fold 7: How the first ‘Ultra’ foldable compares to last year’s model
    • Sakana AI Releases Fugu-Cyber: An Orchestration Model Reporting 86.9% on CyberGym and 72.1% on CTI-REALM
    • Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, July 26
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 26, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances.

    The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13, 2026. The list of affected Packagist packages is below –

    • dinushchathurya/nationality-list
    • dinushchathurya/srilankan-divisional-secretariats
    • dinushchathurya/srilankan-gn-divisions
    • dinushchathurya/srilankan-local-authorities
    • dinushchathurya/srilankan-mobile-number-validator
    • dinushchathurya/srilankan-state-hospitals
    • dinushchathurya/srilankan-universities
    • dinushchathurya/uk-mobile-number-validator
    • dinushchathurya/uk-post-code
    • dinushchathurya/websmslk

    “The PHP libraries were not the execution path,” Socket said in a statement. “Attackers had added dozens of malicious GitHub Actions workflows to the compromised maintainer’s source repositories.”

    Cybersecurity

    The workflows, once triggered by a repository push or manual run, launch GitHub-hosted runners, download a Linux payload from attacker-controlled infrastructure, and scan for vulnerable cPanel and WHM servers susceptible to CVE-2026-41940, an authentication bypass vulnerability that allows remote attackers to gain elevated control of the control panel.

    The payload, for its part, attempts an authentication bypass, and then proceeds to harvest credentials, configuration files, environment variables, database access, SSH material, Git tokens, cloud keys, payment service credentials, and other valuable secrets.

    The exact method by which the threat actor gained unauthorized access to the developer’s account and pushed malicious changes to the repositories remains unclear.

    “Between July 12 and 13, 2026, Packagist automatically synchronized malicious development versions across all ten packages associated with the compromised developer, reflecting changes the threat actor pushed to the developer’s GitHub repositories,” Socket researcher Kirill Boychenko said.

    Each of the affected development versions has been found to contain anywhere between 55 and 62 malicious GitHub Actions workflow files, totaling 583 files across all ten package versions.

    Specifically, the YAML automation files launch GitHub-hosted runners when the compromised repository receives a push or when the workflow is manually launched, detect each runner’s processor architecture (e.g., 32-bit x86, 64-bit x86, 32-bit ARM, and 64-bit ARM systems), and download a compatible Linux scanning and exploitation payload from the command and control (C2) server at 43.228.157[.]68.

    “The workflows continuously report execution status to the threat actor and upload newly collected results through HTTP POST requests,” Boychenko added. “The output files they monitor include AWS credentials, GitHub and GitLab tokens, OpenAI and Google API credentials, Stripe keys, SendGrid and Mailgun credentials, database information, SSH data, Git remotes, and remote code execution results.”

    Unlike other traditional malicious package campaigns, the latest activity does not rely on package users’ systems. Instead, the scanning and exploitation run on GitHub-hosted runners launched from compromised repositories, meaning GitHub Actions is abused to power an exploitation campaign aimed at hunting for vulnerable cPanel and WHM servers.

    Signs point to a broader campaign that extends beyond one PHP maintainer, with roughly 6,100 workflow files hosted on GitHub containing a unique DNSHook identifier (“f5b0b742-240a-4811-8a5b-b0ba6060685d”).

    Socket described the campaign as a case of “opportunistic server-side credential theft operation,” allowing the attackers to leverage the stolen data for follow-on compromises or monetization pathways.

    The disclosure comes as the application security firm also detailed a campaign codenamed Operation Muck and Load that abuses a network of 200 GitHub repositories across 190 accounts to deliver Windows-based malware, including information stealers, loaders and downloaders, droppers, spyware, remote access trojans, and Monero cryptocurrency miners.

    Cybersecurity

    The repositories, some of which masquerade as developer utilities and cryptocurrency wallet integrations, conceal a multi-stage attack chain that downloads a PowerShell script responsible for querying various dead drop sites like Pastebin, Rlim, Telegram, YouTube, Instagram, Google Docs, and Gitcode to fetch a GitHub-hosted password-protected archive, from which the main payload is extracted and launched.

    “The GitHub repositories in this cluster were not only lures,” Boychenko said. “Several also functioned as malware-bearing repositories, embedding malicious payloads directly in the source tree or delivering them through GitHub release assets.”

    The activity shares tactical overlaps with previously observed activity associated with the “ischhfd83@rambler[.]ru” email address, which has been tracked under the moniker Water Curse by Trend Micro. The threat cluster is assessed to operate a GitHub-based ghost network to redirect unsuspecting users to GitHub pages hosting malware-laced payloads.

    “This model gives threat actors a scalable way to turn ordinary software discovery into malware staging, especially when the lures target users already inclined to run untrusted tools, such as crypto automation, wallet utilities, game cheats, crypters, and offensive tooling,” Socket said.

    Actions Attackers cPanel GitHub Runners Servers Target Weaponize WHM
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    How Synthetic Identity Fraud is Coming for Machine Identities

    China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

    Rockwell Patches Code Execution Flaws in Arena Simulation Software

    Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

    July 26, 2026

    Robinhood Chain’s real-world assets jump fivefold as tokenized stocks start trading in size

    July 26, 2026

    Oral GLP-1 drugs may quiet the brain’s food craving circuit

    July 26, 2026

    Does Quaker instant strawberries and cream oatmeal contain castoreum from beaver butts?

    July 26, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

    July 26, 2026

    Robinhood Chain’s real-world assets jump fivefold as tokenized stocks start trading in size

    July 26, 2026

    Oral GLP-1 drugs may quiet the brain’s food craving circuit

    July 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.