Just in:
Qatar economy contracts 7% as energy output slumps // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Apple raises evidence-destruction claims against OpenAI // Chinese researchers engineer self-contracting muscle grafts // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // LatAm gushers and possible Venezuela exit a nightmare for Opec // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // Jungheinrich Marks 25 Years In Singapore, Leading APAC Strategic Hub And Electrification In The Market // WisPaper Introduces TrueCite to Help Researchers Verify AI-Generated Academic References // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Best Mart 360 Reports Interim Revenue Growth to HK$1.45 billion // Haldwani purification row: Caste back on political centre-stage // Venezuela defends sovereignty after Trump oil control claim // What Shein’s $27bn IPO means for Mubadala // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // Trump rejects munitions fears as Iran clashes resume // India plans own orbital space outpost, second after China // Jordan downs eight missiles as Iran targets US bases //

GitHub workflows weaponised to raid hosting servers

Hackers have hijacked GitHub Actions workflows across compromised repositories to create a distributed attack network targeting cPanel and WebHost Manager servers, exposing credentials, databases and cloud accounts.

The campaign uses GitHub-hosted computing systems as disposable machines for scanning the internet, exploiting vulnerable hosting platforms and transmitting stolen information to attacker-controlled infrastructure. Security researchers linked the activity to malicious workflow files planted in thousands of repositories.

The investigation began with suspicious development versions of 10 PHP packages on Packagist, a repository used by developers working with the Composer dependency manager. The packages belonged to a legitimate PHP and DevOps developer whose associated GitHub repositories had been compromised.

Between July 12 and 13, attacker-controlled changes were automatically synchronised from GitHub to the packages’ development branches. Analysts found 583 malicious GitHub Actions workflow files across the 10 versions, with each package containing between 55 and 62 files.

The underlying PHP libraries did not contain malicious installation scripts or code designed to run on users’ computers. Instead, the attack instructions were concealed within the repositories’. github/workflows directories, which control automated development and deployment tasks.

Installing the affected packages through Packagist would not ordinarily activate the malicious files because GitHub does not execute workflow definitions nested inside a project’s dependency directory. The workflows were triggered when changes were pushed to the compromised source repositories or when an attacker launched them manually.

Each workflow instructed GitHub to create a temporary Ubuntu-based runner. These virtual machines, normally used to test software or automate releases, were converted into short-lived attack nodes with internet access.

The workflows identified the processor architecture of each runner and downloaded a matching Linux executable from an external server. Separate payloads were available for 32-bit and 64-bit x86 systems, as well as ARM and ARM64 environments.

Once launched, the software scanned internet-facing systems on ports commonly used by websites and hosting control panels. Its main target was CVE-2026-41940, an authentication bypass vulnerability affecting cPanel and WHM deployments.

cPanel allows customers to manage websites, databases, email accounts and configuration files. WHM gives hosting administrators broader control over servers and multiple cPanel accounts. A successful WHM compromise can therefore expose numerous websites and customer environments through a single intrusion.

The payload searched breached servers for Amazon Web Services keys, GitHub and GitLab access tokens, database passwords, SSH credentials and environment files. It also sought OpenAI and Google API credentials, Stripe payment keys and tokens linked to email services such as SendGrid and Mailgun.

Stolen source-control credentials could allow the attackers to enter more repositories, implant additional workflows and expand the operation. This creates a self-reinforcing supply-chain threat in which credentials obtained from hosting servers can be used to compromise development infrastructure.

The workflows maintained constant contact with the command-and-control server. A heartbeat mechanism reported their status every 30 seconds, identifying the repository and sending the latest scanning activity to the operators.

Collected data was uploaded in batches through repeated web requests. The system tracked which information had already been transmitted, allowing it to send new credentials and exploitation results without duplicating earlier material. A final collection process operated even when the scanner stopped unexpectedly.

Researchers identified a distinctive DNS callback used to verify that commands had executed. Searches for that marker found about 6,100 matching workflow files across unrelated GitHub repositories. Broader searches involving the payload server, scanning instructions and data-exfiltration code returned between 15,000 and 16,000 matching files.

Those figures do not represent an equal number of confirmed victims. A repository can contain several copies of the workflow, while some accounts may have been created or controlled directly by the attackers. The repeated code across projects with unrelated development histories nevertheless indicates a campaign extending well beyond the original PHP packages.

GitHub suspended the account linked to the Packagist packages, disrupting one route used by the operators. Matching workflows may still remain in forks, mirrors, cached repositories and other compromised accounts, while exposed servers and stolen credentials could continue to support further attacks.

Repository owners have been urged to inspect workflow directories, disable unauthorised automation and preserve GitHub Actions logs for investigation. Credentials, access tokens and application secrets connected to affected systems should be replaced.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
What Shein’s $27bn IPO means for Mubadala // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // Haldwani purification row: Caste back on political centre-stage // Venezuela defends sovereignty after Trump oil control claim // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Trump rejects munitions fears as Iran clashes resume // Russia brings cryptocurrency market law into force // Schnabel urges programmable central bank money on-chain // Apple raises evidence-destruction claims against OpenAI // Putin holds talks with Pezeshkian in Bishkek // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Alpha Dhabi lifts MICAD commitment to $1 billion // LatAm gushers and possible Venezuela exit a nightmare for Opec // Jordan downs eight missiles as Iran targets US bases // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment // Qatar economy contracts 7% as energy output slumps // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Adobe widens Saudi AI access with $4 billion programme // Jungheinrich Marks 25 Years In Singapore, Leading APAC Strategic Hub And Electrification In The Market //