Cybersecurity experts have revealed a significant cyber campaign leveraging compromised GitHub repositories to launch attacks on cPanel and WebHost Manager (WHM) servers. This operation primarily targets instances with vulnerabilities, posing a serious threat to web administrators.
Compromised Repositories Fuel Cyber Attacks
In this scheme, attackers have infiltrated GitHub repositories linked to the PHP and DevOps developer dinushchathurya, deploying malicious actions across 10 packages during July 12-13, 2026. The compromised packages include nationality lists, mobile validators, and local authorities data, among others.
Rather than using the PHP libraries directly for attacks, the perpetrators uploaded harmful GitHub Actions workflows into the developer’s repositories. These workflows, when activated, initiate GitHub-hosted runners that download a Linux payload. This payload is designed to exploit a known vulnerability (CVE-2026-41940) in cPanel and WHM servers, potentially allowing attackers to gain unauthorized access.
Insight into Attack Mechanisms
The attack’s mechanism involves bypassing authentication and collecting sensitive data such as credentials, environment variables, and cloud service keys. Although the exact method of the initial breach into the developer’s account remains unknown, the consequences have been significant, with 583 malicious workflow files detected across all affected packages.
These workflows identify the architecture of each runner they encounter and download a compatible exploitation payload from a command and control server. The attackers continuously receive status updates and newly acquired data through HTTP requests, highlighting the operation’s sophistication and threat level.
Beyond Traditional Malware Campaigns
Unlike typical malicious campaigns that exploit end-user systems, this operation uses GitHub’s infrastructure to scan for vulnerable servers. The campaign has expanded to involve over 6,100 workflow files across GitHub, indicating a widespread attempt to gather server-side credentials for further exploitation or sale.
Additionally, the attackers have orchestrated another campaign named Operation Muck and Load, employing a network of 200 GitHub repositories to distribute Windows-based malware. This includes information stealers and cryptocurrency miners, often masked as legitimate developer tools or wallet integrations.
This strategy of embedding malicious code within GitHub repositories represents a new frontier in cyber threats, emphasizing the need for enhanced vigilance and security protocols among developers and IT professionals.
With ongoing investigations, security firms are actively working to mitigate these threats and protect vulnerable systems from future attacks. The situation underscores the critical importance of maintaining robust cybersecurity measures and monitoring for unusual activity within development environments.
