Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
Overview
Cybersecurity researchers have uncovered a significant campaign that exploits compromised GitHub repositories to launch attacks against cPanel and WebHost Manager (WHM) servers. The attackers are using malicious versions of 10 different packages linked to a PHP and DevOps developer known as dinushchathurya. This activity took place between July 12 and 13, and it effectively turns these repositories into a distributed attack infrastructure. This incident is concerning because it puts many web hosting providers and their clients at risk, as cPanel and WHM are widely used for managing web hosting services. Companies need to be vigilant and ensure their systems are secure against these types of attacks, which could lead to unauthorized access or data breaches.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: cPanel, WebHost Manager (WHM), GitHub repositories
- Action Required: Users should review their GitHub repositories for any unauthorized changes, update to the latest versions of cPanel and WHM, and enable security features like two-factor authentication.
- Timeline: Ongoing since July 12-13, 2023
Original Article Summary
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13,
Impact
cPanel, WebHost Manager (WHM), GitHub repositories
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since July 12-13, 2023
Remediation
Users should review their GitHub repositories for any unauthorized changes, update to the latest versions of cPanel and WHM, and enable security features like two-factor authentication.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware.