Socket is an application security firm that identified a large-scale campaign abusing GitHub Actions runners to target cPanel and WHM servers. The campaign involves compromised Packagist packages and malicious workflows that scan for vulnerable servers and steal credentials.