logo

222 GitHub Repositories Linked to Fake Go Package Malware Operation

ID: 1782b564-a130-5b06-bf14-837d742629c6

STIX ID: report--1782b564-a130-5b06-bf14-837d742629c6

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-07-10

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

Researchers uncovered an organized campaign—tracked as “Muck and Load”—that used 222 GitHub repositories and a malicious Go module to masquerade as legitimate projects and deliver a staged malware chain (loaders, Vidar-like stealers, RATs, and XMRig cryptominers). The operation relied on automated GitHub Actions to fabricate active development, public dead-drop sources for encrypted payload locations, and multi-stage PowerShell loaders that disable execution policies and extract password-protected payloads from GitHub releases; platform owners have been notified and some artifacts were blocked.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.