Packagist Conductors A.I CyberSecurity Scoring
Packagist Conductors
Company Information
Website:https://packagist.com
Employees number:8
Number of followers:902
NAICS:
Industry Type:Information Technology & Services
Homepage:packagist.com
Packagist Conductors Risk Score (AI oriented)
Between 700 and 749
Packagist ConductorsInformation Technology & Services
Updated:
23/07/2026
23/07/2026
733/1000
Moderate
Ba
Packagist Conductors Global Score (TPRM)
xxxx
Packagist ConductorsInformation Technology & Services
Score locked

Packagist ConductorsModerate
Current Score
733Ba (MODERATE)
01000
1 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
733
JULY 2026
752
Cyber Attack
12 Jul 2026 • Packagist Conductors
Packagist, WHM, cPanel and GitHub: Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials
Large-Scale Cyber Campaign Hijacks GitHub Actions to Target Web Hosting Servers
733
CRITICAL-19
WHMPACGITCPA1784816835
Large-Scale Cyber Campaign Hijacks GitHub Actions to Target Web Hosting Servers
A sophisticated cyber campaign is exploiting GitHub Actions to weaponize trusted open-source projects, turning them into tools for scanning and compromising web hosting servers. The attack, uncovered by analysts at Socket.dev, abuses free GitHub compute resources to target cPanel and WHM servers critical infrastructure for managing websites, email accounts, and databases.
Between July 12 and 13, 2026, attackers compromised a legitimate PHP developer’s Packagist account, injecting malicious GitHub Actions workflow files into ten development versions of their packages. These workflows, containing 55–62 malicious files each, launch temporary Ubuntu runners that download Linux payloads and scan the internet for vulnerable hosts. The campaign extends beyond the initial compromise, with thousands of matching workflow files discovered across unrelated repositories, indicating a broad effort to hijack automation pipelines.
The attack chain begins when a compromised repository triggers a workflow, spinning up an ephemeral GitHub runner. The runner fetches a processor-specific payload from a threat actor-controlled server (43.228.157.68) and exploits CVE-2026-41940, an authentication bypass flaw in cPanel and WHM. Successful breaches expose cloud credentials, payment data, and source control tokens including AWS keys, GitHub/GitLab tokens, OpenAI/Google API keys, Stripe credentials, and SSH material.
The malware exfiltrates stolen data in small chunks via HTTP POST requests, with heartbeats sent every 30 seconds. While installing the affected PHP packages does not directly execute the malware, root-level GitHub Actions in compromised repositories serve as the attack engine. A single WHM compromise can jeopardize multiple customer accounts, databases, and application secrets.
The campaign remains active despite the suspension of one GitHub account, underscoring its persistence. Indicators of compromise include the C2 server IP (43.228.157.68), payload delivery URLs, and the compromised maintainer account (dinushchathurya). Affected Packagist packages span multiple repositories, all tied to the same developer.
Defensive measures include disabling suspicious workflows, rotating credentials, and patching cPanel/WHM systems. The incident highlights the risks of untrusted automation in CI/CD pipelines, echoing past supply chain attacks where stolen credentials enabled further breaches.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
752
MAY 2026
752
APRIL 2026
752
MARCH 2026
752
FEBRUARY 2026
752
JANUARY 2026
752
DECEMBER 2025
752
NOVEMBER 2025
752
OCTOBER 2025
752
SEPTEMBER 2025
752
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Packagist Conductors ??
What was Packagist Conductors's A.I Rankiteo Cyber Score in July 2026 ??
What was Packagist Conductors's A.I Rankiteo Cyber Score in June 2026 ??
What was Packagist Conductors's A.I Rankiteo Cyber Score in May 2026 ??
What was Packagist Conductors's A.I Rankiteo Cyber Score in April 2026 ??
What was Packagist Conductors's A.I Rankiteo Cyber Score in March 2026 ??
What was Packagist Conductors's A.I Rankiteo Cyber Score in February 2026 ??
What was Packagist Conductors's A.I Rankiteo Cyber Score in January 2026 ??
What was Packagist Conductors's A.I Rankiteo Cyber Score in December 2025 ??
What was Packagist Conductors's A.I Rankiteo Cyber Score in November 2025 ??
What was Packagist Conductors's A.I Rankiteo Cyber Score in October 2025 ??
What was Packagist Conductors's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Packagist Conductors's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Packagist Conductors ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Packagist Conductors's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?