Oodaloop Malware Campaign Exploits 222 GitHub Repositories with Fake Go Packages
Article Content
Browse articles
- •222 GitHub repositories used to spread malware via fake Go packages.
- •Over 1,200 versions of the malicious package published since January 2026.
- •Malware types include spyware, trojans, and cryptominers.
A threat actor has created a network of 222 GitHub repositories distributing Windows malware through fake Go packages, known as Operation Muck and Load. The malicious Go module masquerades as a DNS/subdomain scanning tool, loading PowerShell code to fetch malware from public sources. Since January 24, 2026, over 1,200 versions of the package have been published, with 700 identified as malicious. The malware includes spyware, trojan downloaders, infostealers, and cryptominers. The attack targets users who may unknowingly download these fake tools. Socket, a supply chain protection provider, reported the findings, emphasizing the scale of the operation and its deceptive tactics.
Ask AI about this cluster
Answers cite the sources they use
Updated 9d ago How this analysis works
Timeline
2026-01-24
Malicious Go module first published
The threat actor began publishing the fake Go package, which later revealed a larger network of repositories.
Oodaloop2026-07-10
Operation Muck and Load disclosed
Socket reported on the extensive network of repositories and the malware distribution method used.
Securityaffairs.CoMore articles in this cluster (3)
Common questions
How can I identify if I'm affected?
Check for any downloads from the identified GitHub repositories, especially those related to the dnsub project.
What types of malware are included?
The campaign spreads spyware, trojan downloaders, infostealers, and cryptominers.
What should I do if I downloaded the package?
Immediately remove the package and scan your system for malware using updated antivirus software.
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…