Operation Muck and Load used more than 200 GitHub repositories and a malicious Go module to infect Windows systems

Attackers used a network of more than 200 GitHub repositories to trick developers and users into downloading malware on Windows. Socket says the campaign, dubbed Operation Muck and Load, used 222 lure repositories across 190 accounts and a fake Go module posing as a DNS scanning tool based on dnsub. The module secretly ran PowerShell to fetch a resolver from public dead drops including Pastebin, YouTube, Instagram, Telegram, Google Docs, and GitCode, then downloaded and launched payloads such as AsyncRAT, Quasar RAT, Vidar infostealer, spyware, trojan downloaders, and XMRig-related cryptominers.
Why it matters: This is a broad open-source supply-chain and malware delivery operation that can hit developers, enterprise users, and anyone who runs code from untrusted GitHub projects. Organizations should review use of Go packages and GitHub repositories tied to the campaign, block the listed dead-drop services where appropriate, and hunt for PowerShell-based payload delivery on Windows endpoints.

Sources

Network of 200 GitHub Repositories Used for Malware Infection
Ionut Arghire 2026.07.10 100% relevant
This article establishes a distinct campaign centered on Operation Muck and Load, with its own GitHub repository network, malicious Go module, and malware-delivery chain rather than updating an already tracked specific incident.
← Back to all stories