Security · 2h ago
GitHub Actions Abused in Campaign Targeting cPanel Servers
Attackers compromised GitHub repositories to use GitHub Actions runners as distributed infrastructure targeting cPanel and WHM instances. The campaign involved 10 malicious Packagist packages linked to developer dinushchathurya between July 12-13. The abuse turns legitimate CI/CD resources into attack vectors for server compromise.
Meridian48 take
This campaign highlights a growing trend of attackers weaponizing developer tools, but the real story is how easily open-source supply chains can be turned against their users.
Read the full reporting
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers →
The Hacker News
github-actionssupply-chain-attack