CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

July 23, 2026

Cybersecurity researchers have uncovered a large-scale campaign that weaponizes compromised GitHub repositories to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions across 10 packages associated with a legitimate PHP developer, dinushchathurya, between July 12 and 13, 2026. Attackers added dozens of malicious GitHub Actions workflows to the maintainer’s repositories, which launch GitHub-hosted runners, download a Linux payload, and scan for vulnerable cPanel and WHM servers susceptible to CVE-2026-41940, an authentication bypass vulnerability. The payload harvests credentials, configuration files, environment variables, database access, SSH material, Git tokens, cloud keys, and payment service credentials. The campaign does not rely on package users’ systems but instead abuses GitHub Actions to power exploitation. Roughly 6,100 workflow files contain a unique DNSHook identifier, indicating a broader campaign. Socket also detailed Operation Muck and Load, which uses 200 GitHub repositories across 190 accounts to deliver Windows-based malware including information stealers, loaders, droppers, spyware, remote access trojans, and Monero miners. The activity shares overlaps with the Water Curse threat cluster tracked by Trend Micro.

CVEs: CVE-2026-41940

Attack groups: Water Curse

Malware: Monero miner, information stealer, remote access trojan, dropper, spyware, loader

Companies: Socket, Trend Micro

Products: GitHub Actions, cPanel, WebHost Manager (WHM), Packagist