Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories
Reported 09 Jul 2026 by otx · Severity: medium
A malicious Go module posing as a DNS/subdomain scanner exposed a sophisticated Windows malware staging operation utilizing commit-farming workflows, public dead drops, and protected archives to deploy RAT and infostealer malware. The operation, tracked as 'Muck and Load', levera