Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign
released on 2026-07-23 @ 04:25:24 PM
A large-scale campaign exploited GitHub Actions by compromising repositories to launch distributed attacks against cPanel and WHM servers. The operation began with compromised developer accounts, pushing malicious workflow files that executed on GitHub-hosted runners rather than through traditional package installation. These workflows downloaded Linux payloads from command-and-control infrastructure, scanned internet-facing systems, and exploited CVE-2026-41940 to harvest credentials including AWS keys, GitHub tokens, API credentials, database access, SSH materials, and cloud keys. The campaign affected approximately 6,100 to 16,000 workflow files across unrelated repositories, using ephemeral runners as disposable attack infrastructure. Stolen data was exfiltrated through HTTP POST requests with continuous heartbeat monitoring, enabling near-real-time visibility into exploitation operations across distributed infrastructure.