Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    AI models need more data about biology, and OpenAI is paying to create it

    September 16, 2026

    Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial

    September 15, 2026

    AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’

    September 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • AI models need more data about biology, and OpenAI is paying to create it
    • Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial
    • AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’
    • Roundtables: Could AI really kill us all?
    • How Elon Musk and Tesla Forged a New EV Path
    • The Download: AI doomers, whistleblowing agents, and de-aged livers
    • Inside the Inference Hardware Revolution Of 2026
    • What must happen for AI’s trillion-dollar gamble to pay off
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Network of 200 GitHub Repositories Used for Malware Infection
    Cybersecurity

    Network of 200 GitHub Repositories Used for Malware Infection

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 12, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A threat actor has built a network of over 200 GitHub repositories that have been delivering Windows malware, supply chain protection provider Socket reports.

    Dubbed Operation Muck and Load, the campaign involves 222 lure repositories across 190 accounts that contain a Go module designed to trigger the infection chain.

    The module, Socket explains, loads PowerShell code that fetches a resolver from public dead drops to execute Windows malware such as spyware, trojan downloaders, infostealers, and cryptominers.

    To deceive users, the Go module poses as a DNS/subdomain scanning tool built around the legitimate dnsub open source project. Since January 24, 2026, the threat actor has published over 1,200 versions of the package, 700 of which are malicious.

    “The likely cause is not normal release engineering, but the threat actor’s own GitHub Actions workflow repeatedly generating timestamp commits that could be surfaced as Go pseudo-versions,” Socket notes.

    The module contains a PowerShell command that runs before any scanning logic and is hidden using excessive horizontal whitespace. It fetches a PowerShell script executed in a way that evades script-execution policy restrictions.

    Advertisement. Scroll to continue reading.

    In turn, the script fetches from public dead drops a payload that acts as a resolver, downloader, extractor, and launcher. It locates encrypted payload metadata, decrypts a URL, retrieves a password-protected archive, extracts it, and executes its contents.

    Instead of using a single hardcoded payload URL, the threat actor behind Operation Muck and Load uses multiple public platforms to host mirrored encrypted resolver material for operational resilience.

    “The public sources are the dead-drop locations embedded in the script, including Pastebin, Rlim, Muck-themed infrastructure, and fallback locations on public platforms such as YouTube, Instagram, Telegram, Google Docs, and GitCode,” Socket explains.

    Payloads deployed at the end of the execution chain include AsyncRAT, Quasar RAT, a Remcos-style RAT, infostealers, and spyware.

    While most of the repositories associated with Operation Muck and Load acted as lures, others also delivered malware, either embedded into source trees or through GitHub release assets.

    “We identified at least 14 unique confirmed malware files across the analyzed threat actor workflow repositories. The confirmed payload set included trojan loaders and downloaders, Vidar infostealer, dropper/spyware payloads, and XMRig/BitMiner-related Monero cryptominers,” Socket notes.

    Operation Muck and Load, the cybersecurity firm notes, overlaps with previously observed activity associated with the ‘ischhfd83’ email address, which also included Muck-themed domains.

    Related: North Korean Hackers Target Open Source Developers in Supply Chain Attacks

    Related: China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

    Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages

    Related: New ‘Mistic’ RAT Opens Door to Several Ransomware Families

    GitHub infection malware network repositories
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    How ideas of a vast censorship network moved from the online fringe to Trump policy

    August 8, 2026

    V2X Technology Gets a 5G Cellphone Network Solution

    August 7, 2026

    Indigenous Fiber Network Connects Remote Subarctic Towns

    July 31, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • AI models need more data about biology, and OpenAI is paying to create it
    • Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial
    • AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’
    • Roundtables: Could AI really kill us all?
    • How Elon Musk and Tesla Forged a New EV Path

    AI models need more data about biology, and OpenAI is paying to create it

    September 16, 2026

    Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial

    September 15, 2026

    AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’

    September 15, 2026

    Roundtables: Could AI really kill us all?

    September 15, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.