A large-scale campaign abuses compromised GitHub repositories to weaponize GitHub Actions runners as distributed scanning and exploitation infrastructure targeting internet-facing cPanel and WHM systems via CVE-2026-41940. Malicious workflow files download a Linux payload from a C2 server at 43.228.157.68, scan for vulnerable hosts, exploit the authentication bypass, and exfiltrate harvested credentials through chunked HTTP POST requests. The campaign extends far beyond the initially identified compromised Packagist maintainer, with approximately 6,100 to 16,000 matching workflow files identified across unrelated GitHub repositories.
github-actions-abuse
1 post
Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign