← All stories
● Covered by 2 sources · 2 reportsMedium impact

200 GitHub Repositories Used to Spread Malware in 'Operation Muck and Load'

🔄 Updated 83d ago — new reporting from Tom's Hardware
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Threat actor used 200+ GitHub repos to spread malware.
  • 'Operation Muck and Load' involved a fake Go module.
  • Over 700 malicious module versions published since January.
  • The module posed as a DNS scanning tool.
  • Socket reported the activity to Go security, leading to a block.

Malware Campaign Uncovered

A threat actor has orchestrated a malware distribution campaign using over 200 GitHub repositories. This operation, named 'Operation Muck and Load', employs a malicious Go module that poses as a DNS scanning tool but loads Windows malware.

The campaign involves 222 GitHub repositories across 190 accounts, promoting over 1,200 versions of the module since its first release on January 24, 2023. Out of these, more than 700 versions were identified as malicious.

Execution and Evasion Techniques

The fake Go module includes a PowerShell command disguised with excess whitespace, which fetches a script to evade script-execution policies. It masquerades as a DNS/subdomain scanner built around the dnsub open source project to deceive users.

The threat actor capitalized on GitHub Actions workflow to automate timestamped commit processes, creating pseudo-versions that appeared legitimate.

Implications for Software Supply Chain Security

The discovery by Socket, a supply chain protection provider, underscores vulnerabilities in software repositories like GitHub. The wide dissemination tactic used by the threat actor raises concerns about the security of software supply chains.

As a result of Socket's findings, the malicious Go module has been blocked from the Go module proxy by the Go security team, preventing further proliferation.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A fake Go module disguised as a DNS scanner was found in 222 GitHub repositories, acting as a malware loader. Over 700 malicious versions have been released since its first publication in January 2023, raising concerns about software supply chain security.

A threat actor has utilized over 200 GitHub repositories to deliver Windows malware through a campaign named Operation Muck and Load. This operation leverages a deceptive Go module masquerading as a DNS scanning tool, triggering a chain of infections that distribute various types of malware including spyware and trojans.