Still Circling: Inside the Operator Behind the GitHub Loader

Reported 29 Aug 2026 by otx · Severity: medium

An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected wor