Hackers Abuse GitHub Actions to Target cPanel & WHM Servers
Cybersecurity researchers have uncovered a large-scale campaign where attackers abuse GitHub Actions runners from compromised repositories to target vulnerable cPanel and WebHost Manager (WHM) servers. Instead of infecting developers' devices, the attackers use malicious GitHub workflows to scan the internet for exposed servers and exploit authentication bypass vulnerabilities to gain unauthorized access.


Once a server is compromised, attackers attempt to steal sensitive information, including administrator credentials, SSH keys, cloud access keys, API tokens, database credentials, and configuration files. Researchers also discovered a related campaign using hundreds of GitHub repositories to distribute malware, highlighting how software development platforms are increasingly being weaponized for cyberattacks.
Organizations should immediately patch vulnerable cPanel and WHM installations, secure GitHub repositories with strong authentication, regularly review GitHub Actions workflows, and monitor CI/CD environments for suspicious activity. Strengthening server security and protecting development pipelines are essential to defending against modern supply chain attacks.
NPAV EDR (Endpoint Detection & Response) – Detects, investigates, and responds to advanced attacks targeting servers and endpoints.