← Back to Tech & Science

Hackers Exploit GitHub Actions to Target cPanel Servers via New Vulnerability

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SAN FRANCISCO — Cyberattackers have weaponized compromised repositories on the code-hosting platform GitHub to launch a coordinated campaign against web hosting servers running cPanel and WHM software. The operation, detected early Wednesday morning, leveraged a newly disclosed vulnerability identified as CVE-2026-41940 to infiltrate server infrastructure through automated build systems.

The attack vector involved the abuse of GitHub Actions runners, which are typically used by developers to automate testing and deployment workflows. Threat actors hijacked legitimate developer accounts, including one belonging to a PHP developer known as dinushchathurya, alongside several other compromised repositories. By injecting malicious code into these trusted environments, attackers triggered automated scripts that executed the exploit against targeted servers.

Security researchers identified ten distinct software packages distributed through GitHub that contained the weaponized workflows. When developers or hosting providers integrated these packages into their projects, the embedded malware activated during the build process. The primary objective of the campaign appears to be opportunistic server-side credential theft. By compromising cPanel and WHM servers, attackers aim to harvest administrative credentials for follow-on intrusions or immediate monetization pathways.

The vulnerability exploited in this wave allows remote code execution on affected systems without prior authentication if specific conditions are met within the hosting environment. The timing of the attacks coincides with a surge in automated scanning activity across major cloud providers and shared hosting networks. While the full scope of compromised servers remains under assessment, initial indicators suggest the campaign has reached organizations relying on popular open-source packages for their deployment pipelines.

cPanel Inc., the developer behind the targeted control panel software, has not yet issued a public statement regarding specific mitigation steps or patch availability for CVE-2026-41940. Administrators are advised to audit their GitHub Actions workflows immediately and review access logs on all cPanel-managed servers for unauthorized activity. The compromised repositories have been flagged by platform moderators, but the persistence of malicious forks remains a concern.

Questions remain regarding the identity of the threat actors behind the operation and whether this represents an isolated incident or part of a broader campaign targeting web hosting infrastructure globally. Investigators are also working to determine if any data exfiltration has already occurred from compromised systems before detection. As the attack surface expands, organizations face pressure to secure their supply chains against similar abuses of trusted development platforms.

Discussion

0 / 2000