Compromised Packagist PHP Packages Weaponize GitHub Actions Runners to Target cPanel/WHM Servers (CVE-2026-41940) — Threadlinqs Intelligence
As of 2026-07-25, Compromised Packagist PHP Packages Weaponize GitHub Actions Runners to Target cPanel/WHM Servers (CVE-2026-41940) is a critical-severity supply chain threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 37 indicators of compromise.
Threat ID: TL-2026-1681 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: SUPPLY_CHAIN
Updated: 2026-07-25 · revalidated 1× · latest source
Threat actors compromised the Packagist account of PHP developer dinushchathurya, publishing malicious development versions of 10 packages that ship weaponized GitHub Actions workflows. The workflows
On July 12-13, 2026, Socket researcher Kirill Boychenko identified that ten legitimate Packagist PHP packages published under the account 'dinushchathurya' (nationality-list, srilankan-divisional-secretariats, srilankan-gn-divisions, srilankan-local-authorities, srilankan-mobile-number-validator, srilankan-state-hospitals, srilankan-universities, uk-mobile-number-validator, uk-post-code, and websmslk) had been pushed malicious development versions after the maintainer's account was compromised. Rather than embedding malware in the PHP library code itself, the attackers planted between 55 and 62 malicious GitHub Actions workflow YAML files per package (583 total), designed to trigger on repository pushes or manual dispatch.
When triggered, each workflow spins up a temporary GitHub-hosted Ubuntu runner, fingerprints the runner's processor architecture (32-bit x86, 64-bit x86, 32-bit ARM, 64-bit ARM), and downloads an architecture-matched Linux payload. The payload turns the free, ephemeral GitHub Actions compute into a distributed, opportunistic internet scanner that hunts for internet-facing cPanel and WebHost Manager (WHM) instances vulnerable to CVE-2026-41940, a critical (CVSSv3.1 9.8) CRLF-injection authentication-bypass flaw disclosed and patched by cPanel on 2026-04-28 after roughly two months of suspected zero-day exploitation beginning around 2026-02-23. The flaw lets an unauthenticated remote attacker inject raw \r
sequences via a malicious Basic Authorization header into the cpsrvd session-file write path, omitting an expected segment of the whostmgrsession cookie to bypass its encryption and write attacker-controlled properties (e.g. user=root) into a new session file, yielding full administrative access to the panel, its managed databases, and hosted websites.
Each compromised runner reports status and exfiltrates harvested data to a hardcoded C2 server at 43.228.157.68 via HTTP POST, and every malicious workflow embeds a shared DNSHook tracking identifier (f5b0b742-240a-4811-8a5b-b0ba6060685d) used for callback/telemetry correlation. Socket's GitHub code-search for the DNSHook value alone returned roughly 6,100 matching public workflow files; broader searches pivoting on the C2 IP, scanner CLI arguments, and exfiltration endpoint strings returned 15,000-16,000 matching files, indicating this technique of abusing GitHub Actions minutes as free distributed scanning/attack infrastructure is deployed far beyond the ten confirmed Packagist packages. Beyond cPanel/WHM exploitation, the harvested-data set included AWS credentials, GitHub and GitLab access tokens, OpenAI and Google API keys, Stripe keys, SendGrid and Mailgun credentials, database connection information, SSH key material, git remote URLs, and remote-code-execution output — consistent with a client-side opportunistic credential-theft operation whose proceeds enable follow-on breaches, cloud-resource abuse, or resale. Socket noted overlapping tactics (DNSHook-style tracking, credential-harvesting-as-a-service tooling) with the 'Water Curse' cluster tracked by Trend Micro, associated with the email address ischhfd83@rambler.ru, though attribution is not confirmed.
Separately, CVE-2026-41940 itself was independently and heavily exploited in the wild against the broader population of an estimated 1.5 million internet-exposed cPanel/WHM instances (Shodan), with hosting provider KnownHost and multiple vendors (Rapid7, Cato Networks, eSentire, watchTowr, Hadrian) confirming mass exploitation; CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-04-30.
Weaknesses (CWE)
CWE-93, CWE-287, CWE-306
Target sectors: hostingproviders, webhosting, managedserviceproviders, softwaredevelopment, cloudinfrastructure, smallbusiness
Target regions: Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 37 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, CVE-2026-41940, T1586, T1195, T1583, T1199, T1190, T1020, T1569, T1059, T1550, T1562