Compromised GitHub Actions Repositories Fuel cPanel/WHM Exploitation and Credential Theft

· Original article ↗

Summary

Socket Dev Research found a broad campaign using malicious GitHub Actions workflows in compromised repositories to scan for and exploit cPanel/WHM CVE-2026-41940, then steal credentials. Affected Packagist versions reflected repository compromise; installing them alone,

Key points

  • The campaign used malicious GitHub Actions workflows in compromised repositories to launch temporary GitHub-hosted Linux runners that downloaded and ran a scanner.
  • The scanner targeted internet-facing cPanel and WHM systems for exploitation of CVE-2026-41940, an authentication bypass, and searched for credentials and configuration data.
  • Workflows in ten affected Packagist development versions totaled 583 files, but installing the packages alone did not execute them; the workflows ran from repository roots on pushes or manual launches.
  • The workflows sent execution heartbeats and exfiltrated findings, including cloud and source-control credentials, database information, SSH material, and API keys, to attacker-controlled infrastructure.
  • Researchers found thousands of matching workflow files across unrelated repositories; these counts are files, not confirmed compromised repositories or accounts.
  • The report considered the campaign ongoing at publication. Recommended steps include disabling suspicious workflows, reviewing repository access, rotating exposed credentials, and patching cPanel/WHM.

Article Details

Attack Vectors
  • The threat actor pushed malicious workflow files into compromised GitHub repositories. Repository pushes or manual workflow launches executed them on GitHub-hosted Ubuntu runners.
  • The workflows downloaded an architecture-specific Linux payload from a threat actor-controlled server. The payload scanned internet-facing cPanel and WHM systems and attempted to exploit CVE-2026-41940.
  • The workflows monitored collected credentials and exploitation results, then sent new content to the threat actor through HTTP POST requests. They also sent execution-status heartbeats.
  • Some recovered workflows queried a DNSHook hostname to confirm command execution.
  • Packagist synchronized the compromised repositories into development package versions, but ordinary package installation did not execute the nested workflows.
Defensive Notes
  • Repository owners should disable suspicious workflows, preserve commits and Actions logs, rotate GitHub credentials, review OAuth and GitHub App access, and require approval for changes under .github/workflows.
  • Minimize GITHUB_TOKEN permissions, restrict self-hosted runners, monitor CI egress, and alert on payload downloads from raw IP addresses.
  • Packagist users should avoid unreviewed development versions, verify lockfile commit references, remove affected development versions, and update lockfiles to known-good commits or stable releases.
  • Operators should update cPanel and WHM to a patched build, follow current remediation instructions, and run cPanel’s IOC detection script on servers that remained exposed while unpatched.
  • Where compromise is suspected, rotate potentially exposed server-side credentials and investigate unauthorized sessions and other post-exploitation artifacts.

Indicators of compromise

TypeIndicatorContext
HOSTNAMEf5b0b742-240a-4811-8a5b-b0ba6060685d[.]dnshook[.]siteDNS callback hostname queried by recovered workflows to confirm command execution.
IPV443[.]228[.]157[.]68Threat actor-controlled server used for payload delivery, execution telemetry, and result exfiltration.
SHA25622f721fd3a81d2e27cbf90a122bb977f630c50b79daa98350f0e57b04dfa81f1SHA-256 of the recovered AMD64 Linux payload.
URLhxxp[:]//43[.]228[.]157[.]68/api/dl/386Architecture-specific Linux payload delivery URL.
URLhxxp[:]//43[.]228[.]157[.]68/api/dl/amd64Architecture-specific Linux payload delivery URL.
URLhxxp[:]//43[.]228[.]157[.]68/api/dl/armArchitecture-specific Linux payload delivery URL.
URLhxxp[:]//43[.]228[.]157[.]68/api/dl/arm64Architecture-specific Linux payload delivery URL.
URLhxxp[:]//43[.]228[.]157[.]68/api/github-heartbeatEndpoint receiving execution-status reports from malicious workflows.
URLhxxp[:]//43[.]228[.]157[.]68/api/github-resultsEndpoint receiving exploitation results and harvested data from malicious workflows.

MITRE ATT&CK

T1005 · Data from Local SystemThe payload collected server-side files and data, including configuration, database, SSH, and Git information.T1020 · Automated ExfiltrationWorkflow loops automatically uploaded new lines from collected result files, including a final collection stage.T1041 · Exfiltration Over C2 ChannelThe workflows exfiltrated collected credentials and results to the same threat actor-controlled server used for payload delivery and telemetry.T1059.004 · Unix ShellWorkflow shell commands downloaded and executed the Linux payload and sent results using curl.T1071.001 · Web ProtocolsThe workflows used HTTP POST requests to send status reports and collected results to the threat actor-controlled server.T1071.004 · DNSFourteen recovered workflows made DNS lookups to a DNSHook hostname to confirm command execution.T1074.001 · Local Data StagingThe workflows monitored local scanner output files and tracked line offsets before uploading newly collected results.T1082 · System Information DiscoveryThe workflows detected each runner’s processor architecture to select a matching payload.T1105 · Ingress Tool TransferThe workflows downloaded architecture-specific Linux executables from the threat actor-controlled server onto Actions runners.T1119 · Automated CollectionThe scanner automatically searched for secrets, while workflows monitored and collected newly written result files.T1190 · Exploit Public-Facing ApplicationThe scanner attempted to exploit the CVE-2026-41940 authentication bypass in exposed cPanel and WHM systems.T1195.001 · Compromise Software Dependencies and Development ToolsThe threat actor added malicious GitHub Actions workflows to a developer’s source repositories; Packagist then synchronized the changed development versions.T1496.002 · Bandwidth HijackingThe threat actor used GitHub-hosted runners’ compute and internet connectivity for distributed scanning and exploitation.T1552.001 · Credentials In FilesThe payload searched compromised servers for credentials in configuration files, environment data, SSH material, and other files.T1584.006 · Web ServicesCompromised GitHub repositories launched Actions runners that served as distributed scanning and exploitation infrastructure.T1595.002 · Vulnerability ScanningThe payload scanned internet-facing systems for cPanel and WHM services to target with CVE-2026-41940.

CVE

People

Vendors

Products

Tools

Industries

Related Articles