Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitHub Actions Abused in New Cyberattack on cPanel Servers

GitHub Actions Abused in New Cyberattack on cPanel Servers

Posted on July 23, 2026 By CWS

Cybersecurity experts have revealed a significant cyber campaign leveraging compromised GitHub repositories to launch attacks on cPanel and WebHost Manager (WHM) servers. This operation primarily targets instances with vulnerabilities, posing a serious threat to web administrators.

Compromised Repositories Fuel Cyber Attacks

In this scheme, attackers have infiltrated GitHub repositories linked to the PHP and DevOps developer dinushchathurya, deploying malicious actions across 10 packages during July 12-13, 2026. The compromised packages include nationality lists, mobile validators, and local authorities data, among others.

Rather than using the PHP libraries directly for attacks, the perpetrators uploaded harmful GitHub Actions workflows into the developer’s repositories. These workflows, when activated, initiate GitHub-hosted runners that download a Linux payload. This payload is designed to exploit a known vulnerability (CVE-2026-41940) in cPanel and WHM servers, potentially allowing attackers to gain unauthorized access.

Insight into Attack Mechanisms

The attack’s mechanism involves bypassing authentication and collecting sensitive data such as credentials, environment variables, and cloud service keys. Although the exact method of the initial breach into the developer’s account remains unknown, the consequences have been significant, with 583 malicious workflow files detected across all affected packages.

These workflows identify the architecture of each runner they encounter and download a compatible exploitation payload from a command and control server. The attackers continuously receive status updates and newly acquired data through HTTP requests, highlighting the operation’s sophistication and threat level.

Beyond Traditional Malware Campaigns

Unlike typical malicious campaigns that exploit end-user systems, this operation uses GitHub’s infrastructure to scan for vulnerable servers. The campaign has expanded to involve over 6,100 workflow files across GitHub, indicating a widespread attempt to gather server-side credentials for further exploitation or sale.

Additionally, the attackers have orchestrated another campaign named Operation Muck and Load, employing a network of 200 GitHub repositories to distribute Windows-based malware. This includes information stealers and cryptocurrency miners, often masked as legitimate developer tools or wallet integrations.

This strategy of embedding malicious code within GitHub repositories represents a new frontier in cyber threats, emphasizing the need for enhanced vigilance and security protocols among developers and IT professionals.

With ongoing investigations, security firms are actively working to mitigate these threats and protect vulnerable systems from future attacks. The situation underscores the critical importance of maintaining robust cybersecurity measures and monitoring for unusual activity within development environments.

The Hacker News Tags:attack campaign, cloud security, cPanel, credential theft, Cybersecurity, DevOps security, Exploitation, GitHub actions, GitHub repositories, Linux payload, Malware, Packagist, PHP, remote access, Vulnerabilities

Post navigation

Previous Post: Chick-fil-A Advises Password Change After Security Breach
Next Post: AI Models Struggle with Nuclear-Sabotage Malware Analysis

Related Posts

Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android The Hacker News
Vietnamese Hackers Use PXA Stealer, Hit 4,000 IPs and Steal 200,000 Passwords Globally Vietnamese Hackers Use PXA Stealer, Hit 4,000 IPs and Steal 200,000 Passwords Globally The Hacker News
Apple Tests Encrypted RCS Messaging in iOS Beta Apple Tests Encrypted RCS Messaging in iOS Beta The Hacker News
Google Chrome Can Now Auto-Change Compromised Passwords Using Its Built-In Manager Google Chrome Can Now Auto-Change Compromised Passwords Using Its Built-In Manager The Hacker News
Eclipse Foundation Enhances Security for VS Code Extensions Eclipse Foundation Enhances Security for VS Code Extensions The Hacker News
Researchers Uncover 20+ Configuration Risks, Including Five CVEs, in Salesforce Industry Cloud Researchers Uncover 20+ Configuration Risks, Including Five CVEs, in Salesforce Industry Cloud The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic AI Vulnerability Risks macOS File Access
  • Google Unveils AI-Powered CodeMender for Enhanced Security
  • Abstract Secures $25M to Enhance Security Operations Platform
  • Google Introduces Selfie Video for Account Access Recovery
  • Dolphin X Malware Threatens 300+ Apps with AI Profiling

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic AI Vulnerability Risks macOS File Access
  • Google Unveils AI-Powered CodeMender for Enhanced Security
  • Abstract Secures $25M to Enhance Security Operations Platform
  • Google Introduces Selfie Video for Account Access Recovery
  • Dolphin X Malware Threatens 300+ Apps with AI Profiling

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark