CVE Tools
Back to feed
Exploited in the wild GitHub Actions malware Packagist packages GitHub supply-chain

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

Researchers uncovered a large-scale cyber campaign where attackers leveraged compromised GitHub repositories to deploy malicious workflows targeting cPanel and WebHost Manager (WHM) servers. Between July 12 and 13, 2026, ten Packagist packages linked to a legitimate PHP developer were used to distribute malicious GitHub Actions workflows. These workflows trigger GitHub-hosted runners that download payloads exploiting CVE-2026-41940, an authentication bypass flaw in cPanel and WHM. The attacks aim to steal credentials, configuration files, and sensitive data from vulnerable systems. This incident highlights how supply chain vulnerabilities can be weaponized at scale.