Skip to content
Malware Campaign Exploits 222 GitHub Repositories with Fake Go Packages

Malware Campaign Exploits 222 GitHub Repositories with Fake Go Packages

First seen 10 Jul 2026, 19:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 14:16 UTC
  • •222 GitHub repositories used to spread malware via fake Go packages.
  • •Over 1,200 versions of the malicious package published since January 2026.
  • •Malware types include spyware, trojans, and cryptominers.

A threat actor has created a network of 222 GitHub repositories distributing Windows malware through fake Go packages, known as Operation Muck and Load. The malicious Go module masquerades as a DNS/subdomain scanning tool, loading PowerShell code to fetch malware from public sources. Since January 24, 2026, over 1,200 versions of the package have been published, with 700 identified as malicious. The malware includes spyware, trojan downloaders, infostealers, and cryptominers. The attack targets users who may unknowingly download these fake tools. Socket, a supply chain protection provider, reported the findings, emphasizing the scale of the operation and its deceptive tactics.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-01-24
Malicious Go module first published
The threat actor began publishing the fake Go package, which later revealed a larger network of repositories.
Oodaloop
2026-07-10
Operation Muck and Load disclosed
Socket reported on the extensive network of repositories and the malware distribution method used.
Securityaffairs.Co

More articles in this cluster (3)

Common questions

How can I identify if I'm affected?
Check for any downloads from the identified GitHub repositories, especially those related to the dnsub project.
What types of malware are included?
The campaign spreads spyware, trojan downloaders, infostealers, and cryptominers.
What should I do if I downloaded the package?
Immediately remove the package and scan your system for malware using updated antivirus software.