Back to Feed
Supply ChainJul 22, 2026

Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign

GitHub Actions abuse powers campaign exploiting cPanel/WHM for credential harvesting.

Summary

A large-scale campaign is abusing GitHub Actions by weaponizing compromised repositories to host scanning and exploitation payloads. These payloads target cPanel and WHM systems, exploiting CVE-2026-41940 to harvest sensitive credentials and data. The attack chain leverages GitHub-hosted runners as distributed infrastructure, with malicious development versions of PHP packages acting as a vector to synchronize the compromised workflows.

Full text

Research/Security News11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload11 malicious NuGet tools pose as game cheats to deploy Windows payloads, track hosts, and use Google Sheets for telemetry and control.By Kush Pandya - Jul 14, 2026

Indicators of Compromise

  • cve — CVE-2026-41940
  • ip — 43.228.157.68
  • domain — f5b0b742-240a-4811-8a5b-b0ba6060685d.dnshook.site
  • hash_sha256 — 22f721fd3a81d2e27cbf90a122bb977f630c50b79daa98350f0e57b04dfa81f1
  • url — hxxp://43.228.157.68:80/api/dl/386
  • url — hxxp://43.228.157.68:80/api/dl/amd64
  • url — hxxp://43.228.157.68:80/api/dl/arm
  • url — hxxp://43.228.157.68:80/api/dl/arm64
  • url — hxxp://43.228.157.68:80/api/github-heartbeat
  • url — hxxp://43.228.157.68:80/api/github-results

Entities

cPanel (product)WHM (product)GitHub Actions (product)Packagist (product)Linux (technology)dinushchathurya (threat_actor)