Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitHub Actions Abused in New Cyberattack on cPanel Servers

GitHub Actions Abused in New Cyberattack on cPanel Servers

Posted on July 23, 2026 By CWS

Cybersecurity experts have revealed a significant cyber campaign leveraging compromised GitHub repositories to launch attacks on cPanel and WebHost Manager (WHM) servers. This operation primarily targets instances with vulnerabilities, posing a serious threat to web administrators.

Compromised Repositories Fuel Cyber Attacks

In this scheme, attackers have infiltrated GitHub repositories linked to the PHP and DevOps developer dinushchathurya, deploying malicious actions across 10 packages during July 12-13, 2026. The compromised packages include nationality lists, mobile validators, and local authorities data, among others.

Rather than using the PHP libraries directly for attacks, the perpetrators uploaded harmful GitHub Actions workflows into the developer’s repositories. These workflows, when activated, initiate GitHub-hosted runners that download a Linux payload. This payload is designed to exploit a known vulnerability (CVE-2026-41940) in cPanel and WHM servers, potentially allowing attackers to gain unauthorized access.

Insight into Attack Mechanisms

The attack’s mechanism involves bypassing authentication and collecting sensitive data such as credentials, environment variables, and cloud service keys. Although the exact method of the initial breach into the developer’s account remains unknown, the consequences have been significant, with 583 malicious workflow files detected across all affected packages.

These workflows identify the architecture of each runner they encounter and download a compatible exploitation payload from a command and control server. The attackers continuously receive status updates and newly acquired data through HTTP requests, highlighting the operation’s sophistication and threat level.

Beyond Traditional Malware Campaigns

Unlike typical malicious campaigns that exploit end-user systems, this operation uses GitHub’s infrastructure to scan for vulnerable servers. The campaign has expanded to involve over 6,100 workflow files across GitHub, indicating a widespread attempt to gather server-side credentials for further exploitation or sale.

Additionally, the attackers have orchestrated another campaign named Operation Muck and Load, employing a network of 200 GitHub repositories to distribute Windows-based malware. This includes information stealers and cryptocurrency miners, often masked as legitimate developer tools or wallet integrations.

This strategy of embedding malicious code within GitHub repositories represents a new frontier in cyber threats, emphasizing the need for enhanced vigilance and security protocols among developers and IT professionals.

With ongoing investigations, security firms are actively working to mitigate these threats and protect vulnerable systems from future attacks. The situation underscores the critical importance of maintaining robust cybersecurity measures and monitoring for unusual activity within development environments.

The Hacker News Tags:attack campaign, cloud security, cPanel, credential theft, Cybersecurity, DevOps security, Exploitation, GitHub actions, GitHub repositories, Linux payload, Malware, Packagist, PHP, remote access, Vulnerabilities

Post navigation

Previous Post: Chick-fil-A Advises Password Change After Security Breach
Next Post: AI Models Struggle with Nuclear-Sabotage Malware Analysis

Related Posts

Chrome 0-Day, AI Hacking Tools, DDR5 Bit-Flips, npm Worm & More Chrome 0-Day, AI Hacking Tools, DDR5 Bit-Flips, npm Worm & More The Hacker News
New “Cavalry Werewolf” Attack Hits Russian Agencies with FoalShell and StallionRAT New “Cavalry Werewolf” Attack Hits Russian Agencies with FoalShell and StallionRAT The Hacker News
Google Introduces 24-Hour Delay for Unverified App Installs Google Introduces 24-Hour Delay for Unverified App Installs The Hacker News
CISA Updates KEV Catalog with Four Actively Exploited Software Vulnerabilities CISA Updates KEV Catalog with Four Actively Exploited Software Vulnerabilities The Hacker News
Google Brings AirDrop Compatibility to Android’s Quick Share Using Rust-Hardened Security Google Brings AirDrop Compatibility to Android’s Quick Share Using Rust-Hardened Security The Hacker News
Why IT Leaders Must Rethink Backup in the Age of Ransomware Why IT Leaders Must Rethink Backup in the Age of Ransomware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Introduces Selfie Video for Account Access Recovery
  • Dolphin X Malware Threatens 300+ Apps with AI Profiling
  • AI Models Struggle with Nuclear-Sabotage Malware Analysis
  • GitHub Actions Abused in New Cyberattack on cPanel Servers
  • Chick-fil-A Advises Password Change After Security Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Introduces Selfie Video for Account Access Recovery
  • Dolphin X Malware Threatens 300+ Apps with AI Profiling
  • AI Models Struggle with Nuclear-Sabotage Malware Analysis
  • GitHub Actions Abused in New Cyberattack on cPanel Servers
  • Chick-fil-A Advises Password Change After Security Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark