A large-scale cyber campaign is abusing GitHub Actions to turn trusted open source projects into weapons against web hosting servers. Attackers plant malicious workflow files inside compromised repositories and use free GitHub compute power to scan the public internet for weak targets. The operation focuses on cPanel and WHM servers, which manage websites, email accounts, and databases for countless businesses. Once inside those systems, the malware hunts for cloud keys, payment credentials, and source control tokens that can open more doors. Analysts from Socket.dev identified the campaign while reviewing suspicious Packagist development versions tied to a legitimate PHP developer. Socket.dev said in a report shared with...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!