<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Php on CuraSec</title><link>https://curasec.metacog.co.kr/tags/php/</link><description>Recent content in Php on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 23 Jul 2026 12:47:45 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/php/index.xml" rel="self" type="application/rss+xml"/><item><title>Malicious Packagist Packages Weaponize GitHub Actions to Hit cPanel/WHM</title><link>https://curasec.metacog.co.kr/insights/2026-07-23-attackers-weaponize-github-actions-runners-to-target-cpanel/</link><pubDate>Thu, 23 Jul 2026 12:47:45 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-23-attackers-weaponize-github-actions-runners-to-target-cpanel/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Active supply-chain compromise of 10 Packagist packages tied to developer dinushchathurya (July 12–13); audit your PHP dependency tree for these packages, remove or pin away from any dev/pre-release versions, and inspect CI/CD build logs for unexpected executions since July 12.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs are surfaced in the summary, but the campaign&amp;rsquo;s use of malicious Packagist dev-version installs inside GitHub Actions runners is a detectable pattern — build a detection for unusual package-manager installs of dev/pre-release versions in pipeline logs and hunt for dinushchathurya package executions since July 12.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This campaign illustrates how a single compromised developer account can turn a public package registry into attack infrastructure; useful context when reviewing third-party dependency risk in your software supply chain policy.&lt;/li>
&lt;/ul></description></item></channel></rss>