socket-dev · Crawled Jul 22, 2026

Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign

3 IoCs
Read original article ↗

AI Summary

A large-scale campaign has abused GitHub Actions by compromising repositories to exploit CVE-2026-41940, a cPanel and WHM authentication bypass vulnerability. Malicious workflow files were pushed to compromised repositories, triggering execution on GitHub-hosted runners that downloaded and ran a Linux-based scanner to target vulnerable servers. The payload scanned for exposed credentials, configuration files, and secrets, exfiltrating them to attacker-controlled infrastructure. This campaign extended beyond a single developer, leveraging distributed infrastructure for scanning, exploitation, and credential harvesting at scale.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
IP 43[.]228[.]157[.]68 Details →
Domain f5b0b742-240a-4811-8a5b-b0ba6060685d[.]dnshook[.]site Details →
SHA-256 22f721fd3a81d2e27cbf90a122bb977f630c50b79daa98350f0e57b04dfa81f1 Details →