Researchers reported a large-scale software supply chain campaign that abused compromised GitHub repositories and malicious GitHub Actions workflows to turn GitHub-hosted Ubuntu runners into disposable scanning and exploitation infrastructure. The activity was first linked to ten Packagist PHP packages associated with the legitimate developer account dinushchathurya, but the PHP packages themselves were benign; the malicious execution path came from injected workflow files committed to the repositories. Investigators identified 583 malicious workflow files in the initial cluster, all tied by code reuse and a shared DNSHook callback, with payloads downloaded from 43[.]228[.]157[.]68.
The workflows scanned internet-facing systems and attempted to exploit cPanel and WHM authentication bypass flaw CVE-2026-41940, then exfiltrated harvested credentials and configuration data. Stolen material reportedly included cloud keys, source-control tokens, API credentials, database secrets, and SSH-related data from exposed servers. Researchers said the campaign was far broader than one maintainer account, finding about 6,100 linked workflow files and 15,000 to 16,000 additional files matching related indicators across GitHub, and warned the operation likely remains active through forks, mirrors, cached snapshots, stolen credentials, and surviving attacker infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The legitimate developer account dinushchathurya, which had been tied to the initial Packagist exposure, was suspended. Researchers warned that the operation could still persist through forks, mirrors, cached snapshots, stolen credentials, and surviving attacker infrastructure.
Using a shared DNSHook callback and code pivots, researchers connected the activity to roughly 6,100 workflow files and found 15,000 to 16,000 additional related files across GitHub. This indicated the campaign extended well beyond a single maintainer or package set.
The malicious workflows downloaded Linux payloads from 43[.]228[.]157[.]68, scanned internet-facing systems, and attempted exploitation of cPanel and WHM authentication bypass vulnerability CVE-2026-41940. The activity sought to harvest credentials and sensitive configuration data from exposed servers.
Researchers identified a supply-chain campaign in which compromised GitHub repositories contained injected GitHub Actions workflow files. The workflows abused GitHub-hosted runners as disposable infrastructure while the associated PHP package contents remained benign.
Attackers inserted dozens of malicious GitHub Actions workflow files into source repositories linked to 10 Packagist development packages tied to the developer dinushchathurya. The compromise occurred between July 12 and 13, 2026, establishing the infrastructure later used to target vulnerable cPanel and WHM servers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcesecurityonline.info
Open sourcesocket.dev
Open sourcesemgrep.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.