Researchers linked 222 GitHub repositories across 190 accounts to a malware distribution campaign dubbed Operation Muck and Load, which used fake Go packages and deceptive software projects to trick developers into importing malicious code. The repositories were dressed up with synthetic GitHub Actions activity, manufactured commit history, and lure themes including cryptocurrency tools, Telegram bots, game cheats, and offensive utilities. Investigators tied the activity to a shared actor email address, ischhfd83@rambler[.]ru, and identified a malicious module, github[.]com/kaleidora/dnsub-scanning-tool, as a first-stage Windows loader.
Once executed, the package launched obfuscated PowerShell, used a dead-drop resolver on public platforms to locate current command-and-control infrastructure, and fetched staged payloads from Muck-themed servers. The infection chain delivered malware including Vidar infostealer, AsyncRAT, Quasar RAT, Remcos-style RATs, spyware, and Monero cryptominers tied to XMRig. Reporting said the operation abused developer trust rather than a flaw in Go itself, but warned that Linux build pipelines, CI/CD runners, developer workstations, and cached credentials remain exposed in mixed-platform environments if malicious modules are pulled into builds.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Socket reported the malicious Go module github[.]com/kaleidora/dnsub-scanning-tool and related GitHub infrastructure to the relevant security teams. This marked an active response step following the campaign's discovery.
Socket assessed with high confidence that the Muck and Load activity was connected to a previously reported repository-backdoor cluster associated with the email address ischhfd83@rambler[.]ru. This added attribution context tying the newly described GitHub operation to earlier malicious infrastructure.
Researchers identified a malware distribution campaign tracked as Operation Muck and Load that used more than 200 GitHub repositories and malicious Go modules to trick developers into importing fake packages. The operation used deceptive repository activity, obfuscated code, and staged payload delivery to distribute malware including RATs, infostealers, spyware, and cryptominers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcesecurityaffairs.com
Open sourcelinuxsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.