securityonline.info 7/23/2026, 4:06:50 AM · external

GitHub Actions Abused to Steal Credentials from PHP Packages

GitHub Actions Abused to Steal Credentials from PHP Packages
CyberSIXT Evidence Panel Source marked as original reporting

THE content reports on a critical cybersecurity alert concerning two active exploits: CVE-2026-16232 and CVE-2026-50522. Researchers uncovered a campaign involving GitHub Actions abuse, which facilitated credential theft and exploitation of cPanel and WHM servers. Approximately 583 malicious workflows linked to PHP packages on Packagist were used, resulting in potential access to 6,100 to 16,000 GitHub repositories.

The attackers, an unattributed threat actor, gained push access to a maintainer's repositories and executed malicious actions without the PHP code being directly compromised. The stolen credentials included AWS keys and database logins. Defenders are advised to patch vulnerabilities, restrict access, and audit workflows.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline