Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Packagist Conductors

Packagist Conductors Vendor Cyber Rating & Cyber Score

packagist.com

Private Packagist is a package repository as a service, made by the creators of Composer - the PHP dependency manager.


Packagist Conductors A.I CyberSecurity Scoring

Packagist Conductors
Company Information
Website:https://packagist.com
Employees number:8
Number of followers:902
NAICS:
Industry Type:Information Technology & Services
Homepage:packagist.com
Packagist Conductors Risk Score (AI oriented)
Between 700 and 749
logo
Packagist ConductorsInformation Technology & Services
Updated:
23/07/2026
733/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Packagist Conductors Global Score (TPRM)
xxxx
logo
Packagist ConductorsInformation Technology & Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Packagist Conductors
Packagist ConductorsModerate
Current Score
733Ba (MODERATE)
01000
1 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
733Before Incident
JULY 2026
752Before Incident
Cyber Attack
12 Jul 2026Packagist Conductors
Packagist, WHM, cPanel and GitHub: Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials

Large-Scale Cyber Campaign Hijacks GitHub Actions to Target Web Hosting Servers

733After Incident
CRITICAL-19
WHMPACGITCPA1784816835
Large-Scale Cyber Campaign Hijacks GitHub Actions to Target Web Hosting Servers A sophisticated cyber campaign is exploiting GitHub Actions to weaponize trusted open-source projects, turning them into tools for scanning and compromising web hosting servers. The attack, uncovered by analysts at Socket.dev, abuses free GitHub compute resources to target cPanel and WHM servers critical infrastructure for managing websites, email accounts, and databases. Between July 12 and 13, 2026, attackers compromised a legitimate PHP developer’s Packagist account, injecting malicious GitHub Actions workflow files into ten development versions of their packages. These workflows, containing 55–62 malicious files each, launch temporary Ubuntu runners that download Linux payloads and scan the internet for vulnerable hosts. The campaign extends beyond the initial compromise, with thousands of matching workflow files discovered across unrelated repositories, indicating a broad effort to hijack automation pipelines. The attack chain begins when a compromised repository triggers a workflow, spinning up an ephemeral GitHub runner. The runner fetches a processor-specific payload from a threat actor-controlled server (43.228.157.68) and exploits CVE-2026-41940, an authentication bypass flaw in cPanel and WHM. Successful breaches expose cloud credentials, payment data, and source control tokens including AWS keys, GitHub/GitLab tokens, OpenAI/Google API keys, Stripe credentials, and SSH material. The malware exfiltrates stolen data in small chunks via HTTP POST requests, with heartbeats sent every 30 seconds. While installing the affected PHP packages does not directly execute the malware, root-level GitHub Actions in compromised repositories serve as the attack engine. A single WHM compromise can jeopardize multiple customer accounts, databases, and application secrets. The campaign remains active despite the suspension of one GitHub account, underscoring its persistence. Indicators of compromise include the C2 server IP (43.228.157.68), payload delivery URLs, and the compromised maintainer account (dinushchathurya). Affected Packagist packages span multiple repositories, all tied to the same developer. Defensive measures include disabling suspicious workflows, rotating credentials, and patching cPanel/WHM systems. The incident highlights the risks of untrusted automation in CI/CD pipelines, echoing past supply chain attacks where stolen credentials enabled further breaches.
INCIDENT DETAILS -
TYPE
Supply Chain Attack
MOTIVATION
Data exfiltration, credential theft, financial gain
IMPACT
Data Compromised: Cloud credentials, payment data, source control tokens (AWS keys, GitHub/GitLab tokens, OpenAI/Google API keys, Stripe credentials, SSH material)Systems Affected: cPanel and WHM servers, web hosting infrastructureOperational Impact: Compromise of multiple customer accounts, databases, and application secretsIdentity Theft Risk: High (exposure of personally identifiable information and credentials)Payment Information Risk: High (Stripe credentials and payment data compromised)
DATA BREACH
Type Of Data Compromised: Credentials, payment data, API keys, SSH materialSensitivity Of Data: High (personally identifiable information, financial data, authentication tokens)Data Exfiltration: Yes (via HTTP POST requests in small chunks)Personally Identifiable Information: Yes (cloud credentials, source control tokens, payment information)
JUNE 2026
752Before Incident
MAY 2026
752Before Incident
APRIL 2026
752Before Incident
MARCH 2026
752Before Incident
FEBRUARY 2026
752Before Incident
JANUARY 2026
752Before Incident
DECEMBER 2025
752Before Incident
NOVEMBER 2025
752Before Incident
OCTOBER 2025
752Before Incident
SEPTEMBER 2025
752Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Packagist Conductors ?
?
What was Packagist Conductors's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Packagist Conductors's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Packagist Conductors's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Packagist Conductors's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Packagist Conductors's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Packagist Conductors's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Packagist Conductors's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Packagist Conductors's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Packagist Conductors's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Packagist Conductors's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Packagist Conductors's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Packagist Conductors's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Packagist Conductors ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Packagist Conductors's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Packagist Conductors Cyber Scoring History | Rankiteo