Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
2,203
Company Posts That Month
17
Language
English
Hacker News Points
-
Post removed?
No
Summary

A large-scale cybersecurity incident involving GitHub Actions and Packagist development versions was uncovered, revealing a campaign that exploited compromised repositories to target cPanel and WHM systems using a CVE-2026-41940 vulnerability. This attack did not rely on the PHP package code itself but rather on malicious GitHub Actions workflow files embedded in the repositories, which were automatically synchronized by Packagist. The threat actor used these workflows to launch temporary Ubuntu systems for scanning and exploiting internet-facing systems, harvesting credentials, and reporting execution statuses. The campaign leveraged GitHub-hosted runners for scanning and exploitation tasks, focusing on obtaining sensitive information like AWS keys, database credentials, and SSH material. The scale of the attack was significant, affecting numerous unrelated repositories and utilizing a unique DNSHook identifier for command execution confirmation. Despite disrupting some paths, the operation is considered ongoing, and affected parties have been advised to take defensive measures, such as disabling suspicious workflows, rotating credentials, and updating vulnerable systems.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.