
CVE-2026-41940: GitHub Actions/cPanel — Credential Theft via Supply Chain (June 2026)
CVE-2026-41940 — GitHub Actions / cPanel
CVE-2026-41940 is a high-severity vulnerability under active exploitation, enabling attackers to abuse compromised GitHub Actions workflows to scan, exploit, and exfiltrate sensitive data from cPanel and WHM systems. The campaign leverages GitHub-hosted runners to execute malicious payloads, resulting in credential and configuration data theft on a global scale.
Attack Vector
Attackers compromised GitHub Actions workflows in packages maintained by dinushchathurya, including those distributed via Packagist. Malicious code executed on GitHub-hosted runners scanned for vulnerable cPanel and WHM instances, exploited CVE-2026-41940, and harvested credentials and configuration files. Exfiltration occurred via attacker-controlled endpoints such as 43.228.157.68 and f5b0b742-240a-4811-8a5b-b0ba6060685d.dnshook.site, using custom API paths (e.g., /api/dl/386, /api/github-results). The operation utilized extensive infrastructure coordination and affected multiple repositories, including dinushchathurya/srilankan-local-authorities and dinushchathurya/websmslk. Attackers also leveraged SHA256 hash 22f721fd3a81d2e27cbf90a122bb977f630c50b79daa98350f0e57b04dfa81f1 for payload verification.
Who Is at Risk
Organizations using cPanel and WHM, especially those integrating third-party or community-maintained GitHub Actions workflows, are at immediate risk. Confirmed affected entities include dinushchathurya and Packagist. Any environment running compromised repositories or workflows, particularly those listed above, should assume exposure.
Patch & Mitigate
- Patch: Apply the vendor-provided fix for CVE-2026-41940 to all cPanel and WHM instances immediately. Check for security advisories from GitHub and Packagist regarding affected workflows and packages.
- Workaround: Temporarily disable untrusted or recently updated GitHub Actions workflows. Audit all third-party package dependencies for compromise.
- Detect: Review GitHub Actions logs for unexpected outbound connections to 43.228.157.68, *.dnshook.site, or suspicious API endpoints (/api/dl/386, /api/github-results). Monitor cPanel/WHM logs for unauthorized access or configuration changes.
MITRE ATT&CK
- T1190 — Exploit Public-Facing Application: Attackers exploited cPanel/WHM via exposed services.
- T1552.001 — Credentials in Files: Harvested and exfiltrated credentials and configuration data from compromised systems.
- T1105 — Ingress Tool Transfer: Malicious payloads delivered and executed via GitHub Actions runners.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

