By Interestana AI Editorial — AI-drafted, human-overseen. How we report
GitHub Actions Runners Used in Attacks on cPanel, WHM

Cybersecurity researchers have identified a large-scale campaign that leverages compromised GitHub repositories to launch distributed attacks against cPanel and WebHost Manager (WHM) servers. This sophisticated operation utilizes malicious Packagist development versions across 10 packages, all linked to a legitimate PHP and DevOps developer named dinushchathurya. The malicious activity was observed between July 12 and July 13.
The attackers exploited GitHub Actions runners, a feature designed to automate software development workflows, by injecting malicious code into these development environments. When legitimate users or systems interacted with these compromised repositories or packages, they inadvertently triggered the execution of the malicious code. This allowed the threat actors to establish a foothold and potentially gain unauthorized access to sensitive server configurations and data.
This campaign highlights a growing trend where attackers are increasingly weaponizing legitimate development infrastructure and tools to conduct their operations. By compromising repositories and injecting malicious code into development packages, threat actors can bypass traditional security measures that might not scrutinize the source code of development dependencies as rigorously as production code. The use of Packagist, a popular package repository for PHP, further amplifies the potential reach of such attacks.
Security analysts are urging developers and system administrators to exercise extreme caution when integrating third-party packages and to implement robust security practices for their GitHub repositories. This includes regular code reviews, strict access controls, and vigilant monitoring of repository activity for any signs of compromise. The specific targeting of cPanel and WHM, widely used control panels for web hosting, suggests a motive to disrupt web hosting services or gain access to hosted websites and their data.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.