Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign
GitHub Actions abuse powers campaign exploiting cPanel/WHM for credential harvesting.
Summary
A large-scale campaign is abusing GitHub Actions by weaponizing compromised repositories to host scanning and exploitation payloads. These payloads target cPanel and WHM systems, exploiting CVE-2026-41940 to harvest sensitive credentials and data. The attack chain leverages GitHub-hosted runners as distributed infrastructure, with malicious development versions of PHP packages acting as a vector to synchronize the compromised workflows.
Full text
Research/Security News11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload11 malicious NuGet tools pose as game cheats to deploy Windows payloads, track hosts, and use Google Sheets for telemetry and control.By Kush Pandya - Jul 14, 2026
Indicators of Compromise
- cve — CVE-2026-41940
- ip — 43.228.157.68
- domain — f5b0b742-240a-4811-8a5b-b0ba6060685d.dnshook.site
- hash_sha256 — 22f721fd3a81d2e27cbf90a122bb977f630c50b79daa98350f0e57b04dfa81f1
- url — hxxp://43.228.157.68:80/api/dl/386
- url — hxxp://43.228.157.68:80/api/dl/amd64
- url — hxxp://43.228.157.68:80/api/dl/arm
- url — hxxp://43.228.157.68:80/api/dl/arm64
- url — hxxp://43.228.157.68:80/api/github-heartbeat
- url — hxxp://43.228.157.68:80/api/github-results