How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign

calendar_today July 22, 2026 person Kirill Boychenko domain socket

Malicious Packagist development versions exposed a broader GitHub Actions campaign that abuses compromised repositories to exploit CVE-2026-41940 , a cPanel and WHM authentication bypass vulnerability, and harvest credentials from affected servers. Our investigation into malicious Packagist development versions associated with a legitimate PHP and DevOps developer, dinushchathurya , uncovered a large-scale GitHub Actions abuse campaign. Although the investigation began in the PHP package ecosystem, the PHP library code itself was not the campaign’s execution mechanism.

open_in_new Read original post