Compromised GitHub Actions Repositories Fuel cPanel/WHM Exploitation and Credential Theft

Summary
Socket Dev Research found a broad campaign using malicious GitHub Actions workflows in compromised repositories to scan for and exploit cPanel/WHM CVE-2026-41940, then steal credentials. Affected Packagist versions reflected repository compromise; installing them alone,
Key points
- The campaign used malicious GitHub Actions workflows in compromised repositories to launch temporary GitHub-hosted Linux runners that downloaded and ran a scanner.
- The scanner targeted internet-facing cPanel and WHM systems for exploitation of CVE-2026-41940, an authentication bypass, and searched for credentials and configuration data.
- Workflows in ten affected Packagist development versions totaled 583 files, but installing the packages alone did not execute them; the workflows ran from repository roots on pushes or manual launches.
- The workflows sent execution heartbeats and exfiltrated findings, including cloud and source-control credentials, database information, SSH material, and API keys, to attacker-controlled infrastructure.
- Researchers found thousands of matching workflow files across unrelated repositories; these counts are files, not confirmed compromised repositories or accounts.
- The report considered the campaign ongoing at publication. Recommended steps include disabling suspicious workflows, reviewing repository access, rotating exposed credentials, and patching cPanel/WHM.
Article Details
- Attack Vectors
- The threat actor pushed malicious workflow files into compromised GitHub repositories. Repository pushes or manual workflow launches executed them on GitHub-hosted Ubuntu runners.
- The workflows downloaded an architecture-specific Linux payload from a threat actor-controlled server. The payload scanned internet-facing cPanel and WHM systems and attempted to exploit CVE-2026-41940.
- The workflows monitored collected credentials and exploitation results, then sent new content to the threat actor through HTTP POST requests. They also sent execution-status heartbeats.
- Some recovered workflows queried a DNSHook hostname to confirm command execution.
- Packagist synchronized the compromised repositories into development package versions, but ordinary package installation did not execute the nested workflows.
- Defensive Notes
- Repository owners should disable suspicious workflows, preserve commits and Actions logs, rotate GitHub credentials, review OAuth and GitHub App access, and require approval for changes under .github/workflows.
- Minimize GITHUB_TOKEN permissions, restrict self-hosted runners, monitor CI egress, and alert on payload downloads from raw IP addresses.
- Packagist users should avoid unreviewed development versions, verify lockfile commit references, remove affected development versions, and update lockfiles to known-good commits or stable releases.
- Operators should update cPanel and WHM to a patched build, follow current remediation instructions, and run cPanel’s IOC detection script on servers that remained exposed while unpatched.
- Where compromise is suspected, rotate potentially exposed server-side credentials and investigate unauthorized sessions and other post-exploitation artifacts.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| HOSTNAME | f5b0b742-240a-4811-8a5b-b0ba6060685d[.]dnshook[.]site | DNS callback hostname queried by recovered workflows to confirm command execution. |
| IPV4 | 43[.]228[.]157[.]68 | Threat actor-controlled server used for payload delivery, execution telemetry, and result exfiltration. |
| SHA256 | 22f721fd3a81d2e27cbf90a122bb977f630c50b79daa98350f0e57b04dfa81f1 | SHA-256 of the recovered AMD64 Linux payload. |
| URL | hxxp[:]//43[.]228[.]157[.]68/api/dl/386 | Architecture-specific Linux payload delivery URL. |
| URL | hxxp[:]//43[.]228[.]157[.]68/api/dl/amd64 | Architecture-specific Linux payload delivery URL. |
| URL | hxxp[:]//43[.]228[.]157[.]68/api/dl/arm | Architecture-specific Linux payload delivery URL. |
| URL | hxxp[:]//43[.]228[.]157[.]68/api/dl/arm64 | Architecture-specific Linux payload delivery URL. |
| URL | hxxp[:]//43[.]228[.]157[.]68/api/github-heartbeat | Endpoint receiving execution-status reports from malicious workflows. |
| URL | hxxp[:]//43[.]228[.]157[.]68/api/github-results | Endpoint receiving exploitation results and harvested data from malicious workflows. |
MITRE ATT&CK
T1005 · Data from Local SystemThe payload collected server-side files and data, including configuration, database, SSH, and Git information.T1020 · Automated ExfiltrationWorkflow loops automatically uploaded new lines from collected result files, including a final collection stage.T1041 · Exfiltration Over C2 ChannelThe workflows exfiltrated collected credentials and results to the same threat actor-controlled server used for payload delivery and telemetry.T1059.004 · Unix ShellWorkflow shell commands downloaded and executed the Linux payload and sent results using curl.T1071.001 · Web ProtocolsThe workflows used HTTP POST requests to send status reports and collected results to the threat actor-controlled server.T1071.004 · DNSFourteen recovered workflows made DNS lookups to a DNSHook hostname to confirm command execution.T1074.001 · Local Data StagingThe workflows monitored local scanner output files and tracked line offsets before uploading newly collected results.T1082 · System Information DiscoveryThe workflows detected each runner’s processor architecture to select a matching payload.T1105 · Ingress Tool TransferThe workflows downloaded architecture-specific Linux executables from the threat actor-controlled server onto Actions runners.T1119 · Automated CollectionThe scanner automatically searched for secrets, while workflows monitored and collected newly written result files.T1190 · Exploit Public-Facing ApplicationThe scanner attempted to exploit the CVE-2026-41940 authentication bypass in exposed cPanel and WHM systems.T1195.001 · Compromise Software Dependencies and Development ToolsThe threat actor added malicious GitHub Actions workflows to a developer’s source repositories; Packagist then synchronized the changed development versions.T1496.002 · Bandwidth HijackingThe threat actor used GitHub-hosted runners’ compute and internet connectivity for distributed scanning and exploitation.T1552.001 · Credentials In FilesThe payload searched compromised servers for credentials in configuration files, environment data, SSH material, and other files.T1584.006 · Web ServicesCompromised GitHub repositories launched Actions runners that served as distributed scanning and exploitation infrastructure.T1595.002 · Vulnerability ScanningThe payload scanned internet-facing systems for cPanel and WHM services to target with CVE-2026-41940.
CVE
People
Vendors
cPanela broader GitHub Actions campaign that abuses compromised repositories to exploit CVE-2026-41940, a cPanel and WHM authentication bypass vulnerability, and harvest credentials from affected servers.GitHubMalicious Packagist development versions exposed a broader GitHub Actions campaign that abuses compromised repositories to exploit CVE-2026-41940, a cPanel and WHM authentication bypass vulnerability, and harvest
Products
cPanela broader GitHub Actions campaign that abuses compromised repositories to exploit CVE-2026-41940, a cPanel and WHM authentication bypass vulnerability, and harvest credentials from affected servers.GitHub ActionsMalicious Packagist development versions exposed a broader GitHub Actions campaign that abuses compromised repositories to exploit CVE-2026-41940, a cPanel and WHM authentication bypass vulnerability, and harvestPackagistMalicious Packagist development versions exposed a broader GitHub Actions campaign that abuses compromised repositories to exploit CVE-2026-41940, a cPanel and WHM authentication bypass vulnerability, and harvestWHMGitHub Actions campaign that abuses compromised repositories to exploit CVE-2026-41940, a cPanel and WHM authentication bypass vulnerability, and harvest credentials from affected servers.
Tools
GitHub Code SearchGitHub Code Search for the campaign’s unique DNSHook hostname, a callback domain that records DNS lookups to confirm command execution, surfaced roughly 6,100 campaign-linked workflow files across unrelated repositories.Socket AI ScannerSocket AI Scanner’s analysis of the malicious dinushchathurya/srilankan-local-authorities@dev-main Packagist version identifies a GitHub Actions workflow that downloads and executes an unverified payload, performs