The record
Written from the 2 reports below. Nothing here is unsourced.
- Security researchers have uncovered two large-scale supply-chain campaigns exploiting developer tooling.
- The first weaponizes compromised GitHub Actions repositories to target vulnerable cPanel and WebHost Manager servers, stealing credentials via an authentication bypass (CVE-2026-41940).
- The second involves 18 malicious npm packages delivering cross-platform remote access trojans, specifically targeting users of Alibaba's @ali scoped developer packages and the Xanadu mrmustard library (v0.7.4).
- Both campaigns are already being actively exploited in the wild.
- The attacks underscore systemic weaknesses in open-source package verification and CI/CD pipeline security, affecting hosting providers, cloud developers, and enterprises relying on these tools.
- Researchers recommend rotating sensitive credentials from clean machines and auditing developer systems for suspicious activity, though no official patches are yet available.
- Watch for vendor advisories from cPanel, GitHub, Alibaba, and Xanadu, and monitor threat feeds for new malicious package variants.
What to watch next
- Rotate cPanel/WHM credentials from clean systems immediately
- Audit npm and GitHub Actions dependencies for @ali and mrmustard usage
- Monitor for vendor patches and advisories from affected vendors
- Check developer endpoints for C2 beacons and suspicious processes
What changed2
Every report on this story, newest first. Times are when each outlet published.
Why it matters4
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- cPanel and WebHost Manager server operators credential theft· immediate
- Alibaba developer tooling users remote code execution· immediate
- GitHub Actions CI/CD pipelines supply chain compromise· days
- npm package consumers malware installation· days
Coverage1
2 reports
English national2
All filed from IndiaSingle origin
Named Alibaba Group · Xanadu · ch4ce · cPanel · dinushchathurya · GitHub · Karlo Zanki · Kirill Boychenko · npm · Packagist · SafeDep · Socket
The 2 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.

