适用于受 CVE-2026-41940 / nuclear.x86 影响的 cPanel 服务器的完整安全工具包。 包含两个脚本 — 一个执行全面审计,另一个通过 Imunify360 实现自动清理。 支持正版授权及绕过/共享授权 — 两种服务器上均可运行。
| 名称 | MD Mahfuz Reham |
| 角色 | 系统管理员 | 虚拟主机专家 |
| 网站 | MahfuzReham.Com |
| +8801790614055 | |
| GitHub | github.com/mahfuzreham |
| 详情 | 信息 |
|---|---|
| CVE ID | CVE-2026-41940 |
| CVSS 评分 | 9.8 — 严重 |
| 影响范围 | 所有受支持的 cPanel 与 WHM 版本 |
| 利用情况 | 在公开披露之前已被积极利用 |
| 恶意软件 | nuclear.x86 Linux 僵尸网络 |
| 攻击者 IP | 87.121.84.78 · 45.148.120.23 |
wget google.com
# 显示 "Killed" → nuclear.x86 仍在运行
# 正常下载完成 → 没有恶意软件,或已被清除
| 脚本 | 功能 | 使用时机 |
|---|---|---|
cpanel_security_check.sh | 服务器全面审计、终止恶意软件、SSH 密钥轮换 | 请先运行此脚本 |
imunify360_scan_clean.sh | 使用 Imunify360 扫描所有账户并清理网页木马 | 随后运行此脚本 |
cd /root && \
wget -O cpanel_security_check.sh \
https://raw.githubusercontent.com/mahfuzreham/cpanel-cve-2026-41940/main/cpanel_security_check.sh && \
wget -O imunify360_scan_clean.sh \
https://raw.githubusercontent.com/mahfuzreham/cpanel-cve-2026-41940/main/imunify360_scan_clean.sh && \
bash cpanel_security_check.sh && \
bash imunify360_scan_clean.sh
⚠️ 必须以 root 身份运行
bash <(curl -s https://raw.githubusercontent.com/mahfuzreham/cpanel-cve-2026-41940/main/cpanel_security_check.sh)
| 检查 | 描述 |
|---|---|
| 🦠 恶意软件进程 | 检测并终止正在运行的 nuclear.x86 进程 |
| 🌐 wget/curl 测试 | 确认恶意软件是否处于活跃状态 |
| 🔌 攻击者 IP | 检查是否存在与 C2 IP 的连接 |
| 📜 历史记录扫描 | 在 Shell 历史记录中查找攻击特征 |
| 📦 cPanel 版本 | 检查上次更新及补丁状态 |
| 🔓 端口暴露 | 检查 2083、2087、2095、2096 端口是否开放 |
| 🗝️ SSH 密钥 | 审计私钥年龄及 authorized_keys |
| ⏰ 定时任务 | 扫描可疑的 cron 条目 |
| 🐚 网页木马 | 在 public_html 中扫描 PHP 网页木马 |
| 🔐 SUID 二进制文件 | 检测异常的 SUID 文件 |
/scripts/upcp --force)bash <(curl -s https://raw.githubusercontent.com/mahfuzreham/cpanel-cve-2026-41940/main/imunify360_scan_clean.sh)
| 步骤 | 操作 |
|---|---|
| 1 | 检查 Imunify360 状态及服务 |
| 2 | 更新恶意软件签名数据库 |
| 3 | 对所有 cPanel 账户进行全面扫描 |
| 4 | 扫描 CVE-2026-41940 网页木马特征 |
| 5 | 自动清理 + 隔离 |
| 6 | 删除可疑文件(含备份) |
| 7 | 启用实时防护 |
| 8 | 设置每日自动扫描定时任务 |
| 9 | 生成完整摘要报告 |
wp-cache-*.php wp-check-*.php wp-sync-*.php
wp-util-*.php admin-init-*.php upgrade-*.php
class-wp-*.php task_*.php .*\.php (hidden)
eval(base64_decode system($_ passthru($_
assert($_ exec($_ shell_exec($_
| cpanel_security_check.sh | imunify360_scan_clean.sh | |
|---|---|---|
| 操作系统 | CentOS / AlmaLinux / CloudLinux / Ubuntu | CentOS / AlmaLinux / CloudLinux / Ubuntu |
| 控制面板 | cPanel & WHM | cPanel & WHM |
| 权限 | Root SSH | Root SSH |
| 软件 | — | Imunify360(已授权) |
wget https://repo.imunify360.cloudlinux.com/defence360/imunify-deploy.sh
bash imunify-deploy.sh --key YOUR_LICENSE_KEY
/root/cpanel_security_audit_TIMESTAMP.log ← 脚本 1 日志
/root/imunify360_cleanup_TIMESTAMP.log ← 脚本 2 日志
/root/imunify360_report_TIMESTAMP.txt ← 受感染文件列表
/root/webshell_backup/ ← 已删除文件的备份
pkill -9 -f "nuclear.x86"
ps auxf | grep nuclear
iptables -I INPUT -p tcp --dport 2083 -j DROP
iptables -I INPUT -p tcp --dport 2087 -j DROP
iptables -I INPUT -p tcp --dport 2095 -j DROP
iptables -I INPUT -p tcp --dport 2096 -j DROP
/scripts/upcp --force
whmapi1 configureservice service=cpsrvd enabled=0 monitored=0 && \
whmapi1 configureservice service=cpdavd enabled=0 monitored=0 && \
/scripts/restartsrv_cpsrvd --stop && \
/scripts/restartsrv_cpdavd --stop
☐ 运行 cpanel_security_check.sh
☐ 运行 imunify360_scan_clean.sh
☐ 重置 cPanel 所有账户的密码
☐ 重置所有 FTP / 邮箱 / MySQL 密码
☐ 更新 wp-config.php / .env 文件
☐ Email 转发器中没有未知转发吧?
☐ 定时任务中没有未知任务吧?
☐ FTP 账户中没有未知账户吧?
☐ 从 GitHub / GitLab 撤销旧 SSH 密钥
☐ WordPress 管理员用户中没有未知用户吧?
☐ 更新所有 WordPress 插件和主题
| 操作系统 | 状态 |
|---|---|
| AlmaLinux 8/9 | ✅ |
| CloudLinux 7/8 | ✅ |
| CentOS 7 | ✅ |
| Rocky Linux 8/9 | ✅ |
| Ubuntu 20/22(cPanel) | ✅ |
MIT 许可证 — 可自由使用、分享和修改。 分享时请保留作者署名。
⚠️ 请将此工具包分享给所有人 — 任何使用 cPanel 服务器的人都可能受到此漏洞的影响。
如果这个工具包帮助您加固了服务器或节省了时间,请考虑支持未来的开发与安全研究。
🔗 捐赠链接: https://pay.shurjopayment.com/d21kNExwjP
您的支持将用于:
每一份贡献都有助于让托管服务器更加安全。感谢您支持本项目 ❤️