Researchers identified a malicious Go module, github.com/kaleidora/dnsub-scanning-tool, that posed as a DNS and subdomain scanning utility while delivering a Windows-focused malware chain. The package reportedly launched hidden PowerShell execution and used dead-drop resolver techniques to retrieve follow-on infrastructure, turning a seemingly legitimate developer tool into an initial access vector for staged payload delivery.
The investigation expanded beyond the single package into a broader GitHub lure network spanning 222 repositories across 190 accounts, which researchers tracked as Operation Muck and Load. The activity was linked to Muck-themed infrastructure and multi-stage loading behavior, and reporting included indicators of compromise such as domains, URLs, file hashes, an email address, and Windows file paths tied to staging and payload execution.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The investigation expanded beyond the single module to a broader GitHub lure network spanning 222 repositories across 190 accounts. Researchers tracked the activity cluster as Operation Muck and Load and published related indicators of compromise.
Researchers found the Go module github.com/kaleidora/dnsub-scanning-tool masquerading as a DNS/subdomain scanner while exposing a Windows-focused malware delivery chain using hidden PowerShell execution and dead-drop resolver techniques.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.