
Researchers Uncover 222 GitHub Repositories Distributing Malware via Fake Go Packages
Breaking NewsCybercrimeMalwareSecurityHackinghacking newsinformation security newsIT Information SecurityMuck and Load campaignGitHubPierluigi PaganiniSecurity AffairsSecurity News
Researchers identified 222 GitHub repositories distributing malware via fake Go packages, part of a broader malicious operation. The campaign, investigated by Socket’s security research team, began with the discovery of a single malicious Go module (github[.]com/kaleidora/dnsub-scanning-tool), which masqueraded as a DNS and subdomain scanning utility. The repositories delivered various payloads, including loaders, stealers, remote access trojans (RATs), and cryptominers. No specific dates, CVE IDs, or victim counts were disclosed in the findings. The operation highlights the abuse of open-source platforms to propagate malware under the guise of legitimate tools.