Bottom line: Attackers weaponize compromised PHP packages and GitHub Actions runners to gain access to cPanel and WHM administration interfaces.
Security researchers have documented a large-scale campaign that abuses compromised GitHub repositories and Actions runners as distributed attack infrastructure against cPanel and WebHost Manager instances. Ten packages on Packagist are affected, distributed under the name of a legitimate PHP developer.
The attack exploits manipulated development versions of PHP packages on Packagist, the standard package repository for PHP. Between July 12 and 13, at least ten packages from the account dinushchathurya were prepared with malicious code to leverage GitHub Actions runners as a springboard for attacks on cPanel and WHM systems.
GitHub Actions runners are installed by default on many development systems to execute automated workflows. By injecting malicious code sequences into widely distributed packages, the attackers gained access to these runners and used them to conduct targeted attacks on the administration interfaces of hosting infrastructure. cPanel and WHM are widely used control panel solutions for hosting providers and dedicated server management.
CISOs should immediately verify whether their development and deployment environments have installed packages from compromised sources. This includes auditing GitHub Actions runners for suspicious activity, reviewing access to cPanel and WHM instances, and reinitializing credentials for these systems. The Packagist repositories should be updated promptly to newer, uncompromised versions.
Source: thehackernews.com · Published July 23, 2026
Lumi AI News — AI-assisted curation according to Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.