Malicious Packagist development versions exposed a broader GitHub Actions campaign that abuses compromised repositories to exploit CVE-2026-41940 , a cPanel and WHM authentication bypass vulnerability, and harvest credentials from affected servers. Our investigation into malicious Packagist development versions associated with a legitimate PHP and DevOps developer, dinushchathurya , uncovered a large-scale GitHub Actions abuse campaign. Although the investigation began in the PHP package ecosystem, the PHP library code itself was not the campaign’s execution mechanism.