Cybersecurity researchers have uncovered a campaign where compromised GitHub repositories are being used as distributed attack infrastructure. This infrastructure is designed to target cPanel and WebHost Manager (WHM) servers.
The attack involves malicious GitHub Actions workflows added to compromised maintainer source repositories. These workflows, when triggered, launch GitHub-hosted runners that download a Linux payload. The payload then scans for vulnerable cPanel and WHM servers susceptible to CVE-2026-41940, an authentication bypass vulnerability.
The payload attempts an authentication bypass and proceeds to harvest credentials, configuration files, environment variables, database access, SSH material, Git tokens, cloud keys, and payment service credentials.
Between July 12 and 13, 2026, malicious development versions were synchronized across ten Packagist packages associated with a legitimate PHP and DevOps developer, dinushchathurya. Each affected development version contained between 55 and 62 malicious GitHub Actions workflow files, totaling 583 files across all ten package versions.
The exact method by which the threat actor gained unauthorized access to the developer's account and pushed these malicious changes remains unclear. This campaign poses a significant risk to cPanel and WHM users, as it can lead to full compromise of their control panels and sensitive data.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A large-scale campaign is using compromised GitHub repositories to create distributed attack infrastructure, targeting cPanel and WebHost Manager (WHM) instances. Malicious GitHub Actions workflows in compromised developer accounts are exploiting CVE-2026-41940 to gain elevated control and harvest credentials from vulnerable servers.