Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    iPhone 18 Pro vs Google Pixel 11 Pro: iOS or Android?

    September 13, 2026

    I’ve tried dozens of Android launchers, but I always end up reinstalling this one

    September 13, 2026

    Think twice before wall mounting that new TV

    September 13, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Network of 200 GitHub Repositories Used for Malware Infection
    Network of 200 GitHub Repositories Used for Malware Infection
    Cybersecurity

    Network of 200 GitHub Repositories Used for Malware Infection

    The Tech GuyBy The Tech GuyJuly 12, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    A threat actor has built a network of over 200 GitHub repositories that have been delivering Windows malware, supply chain protection provider Socket reports.

    Advertisement

    Dubbed Operation Muck and Load, the campaign involves 222 lure repositories across 190 accounts that contain a Go module designed to trigger the infection chain.

    The module, Socket explains, loads PowerShell code that fetches a resolver from public dead drops to execute Windows malware such as spyware, trojan downloaders, infostealers, and cryptominers.

    To deceive users, the Go module poses as a DNS/subdomain scanning tool built around the legitimate dnsub open source project. Since January 24, 2026, the threat actor has published over 1,200 versions of the package, 700 of which are malicious.

    “The likely cause is not normal release engineering, but the threat actor’s own GitHub Actions workflow repeatedly generating timestamp commits that could be surfaced as Go pseudo-versions,” Socket notes.

    The module contains a PowerShell command that runs before any scanning logic and is hidden using excessive horizontal whitespace. It fetches a PowerShell script executed in a way that evades script-execution policy restrictions.

    Advertisement. Scroll to continue reading.

    In turn, the script fetches from public dead drops a payload that acts as a resolver, downloader, extractor, and launcher. It locates encrypted payload metadata, decrypts a URL, retrieves a password-protected archive, extracts it, and executes its contents.

    Instead of using a single hardcoded payload URL, the threat actor behind Operation Muck and Load uses multiple public platforms to host mirrored encrypted resolver material for operational resilience.

    “The public sources are the dead-drop locations embedded in the script, including Pastebin, Rlim, Muck-themed infrastructure, and fallback locations on public platforms such as YouTube, Instagram, Telegram, Google Docs, and GitCode,” Socket explains.

    Payloads deployed at the end of the execution chain include AsyncRAT, Quasar RAT, a Remcos-style RAT, infostealers, and spyware.

    While most of the repositories associated with Operation Muck and Load acted as lures, others also delivered malware, either embedded into source trees or through GitHub release assets.

    “We identified at least 14 unique confirmed malware files across the analyzed threat actor workflow repositories. The confirmed payload set included trojan loaders and downloaders, Vidar infostealer, dropper/spyware payloads, and XMRig/BitMiner-related Monero cryptominers,” Socket notes.

    Operation Muck and Load, the cybersecurity firm notes, overlaps with previously observed activity associated with the ‘ischhfd83’ email address, which also included Muck-themed domains.

    Related: North Korean Hackers Target Open Source Developers in Supply Chain Attacks

    Related: China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

    Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages

    Related: New ‘Mistic’ RAT Opens Door to Several Ransomware Families

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

    September 12, 2026

    BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

    September 12, 2026

    GitLab Vulnerability Exploited One Day After Disclosure

    September 12, 2026

    Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

    September 12, 2026

    Phishing Research Challenges Conventional Security Awareness Testing

    September 11, 2026

    In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    iPhone 18 Pro vs Google Pixel 11 Pro: iOS or Android?

    September 13, 2026

    I’ve tried dozens of Android launchers, but I always end up reinstalling this one

    September 13, 2026

    Think twice before wall mounting that new TV

    September 13, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.