Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitHub Actions Abused in New Cyberattack on cPanel Servers

GitHub Actions Abused in New Cyberattack on cPanel Servers

Posted on July 23, 2026 By CWS

Cybersecurity experts have revealed a significant cyber campaign leveraging compromised GitHub repositories to launch attacks on cPanel and WebHost Manager (WHM) servers. This operation primarily targets instances with vulnerabilities, posing a serious threat to web administrators.

Compromised Repositories Fuel Cyber Attacks

In this scheme, attackers have infiltrated GitHub repositories linked to the PHP and DevOps developer dinushchathurya, deploying malicious actions across 10 packages during July 12-13, 2026. The compromised packages include nationality lists, mobile validators, and local authorities data, among others.

Rather than using the PHP libraries directly for attacks, the perpetrators uploaded harmful GitHub Actions workflows into the developer’s repositories. These workflows, when activated, initiate GitHub-hosted runners that download a Linux payload. This payload is designed to exploit a known vulnerability (CVE-2026-41940) in cPanel and WHM servers, potentially allowing attackers to gain unauthorized access.

Insight into Attack Mechanisms

The attack’s mechanism involves bypassing authentication and collecting sensitive data such as credentials, environment variables, and cloud service keys. Although the exact method of the initial breach into the developer’s account remains unknown, the consequences have been significant, with 583 malicious workflow files detected across all affected packages.

These workflows identify the architecture of each runner they encounter and download a compatible exploitation payload from a command and control server. The attackers continuously receive status updates and newly acquired data through HTTP requests, highlighting the operation’s sophistication and threat level.

Beyond Traditional Malware Campaigns

Unlike typical malicious campaigns that exploit end-user systems, this operation uses GitHub’s infrastructure to scan for vulnerable servers. The campaign has expanded to involve over 6,100 workflow files across GitHub, indicating a widespread attempt to gather server-side credentials for further exploitation or sale.

Additionally, the attackers have orchestrated another campaign named Operation Muck and Load, employing a network of 200 GitHub repositories to distribute Windows-based malware. This includes information stealers and cryptocurrency miners, often masked as legitimate developer tools or wallet integrations.

This strategy of embedding malicious code within GitHub repositories represents a new frontier in cyber threats, emphasizing the need for enhanced vigilance and security protocols among developers and IT professionals.

With ongoing investigations, security firms are actively working to mitigate these threats and protect vulnerable systems from future attacks. The situation underscores the critical importance of maintaining robust cybersecurity measures and monitoring for unusual activity within development environments.

The Hacker News Tags:attack campaign, cloud security, cPanel, credential theft, Cybersecurity, DevOps security, Exploitation, GitHub actions, GitHub repositories, Linux payload, Malware, Packagist, PHP, remote access, Vulnerabilities

Post navigation

Previous Post: Chick-fil-A Advises Password Change After Security Breach
Next Post: AI Models Struggle with Nuclear-Sabotage Malware Analysis

Related Posts

CBI Shuts Down £390K U.K. Tech Support Scam, Arrests Key Operatives in Noida Call Center CBI Shuts Down £390K U.K. Tech Support Scam, Arrests Key Operatives in Noida Call Center The Hacker News
Researchers Detail Windows EPM Poisoning Exploit Chain Leading to Domain Privilege Escalation Researchers Detail Windows EPM Poisoning Exploit Chain Leading to Domain Privilege Escalation The Hacker News
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution The Hacker News
MuddyWater Exploits Teams for Credential Theft in Covert Attack MuddyWater Exploits Teams for Credential Theft in Covert Attack The Hacker News
Enhancing Mobile Security with Samsung Knox Enhancing Mobile Security with Samsung Knox The Hacker News
.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL .NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark