Alex Yao Alex Yao
Back to news
Cyber Security Published on July 10, 2026

Operation Muck and Load: 200+ GitHub repositories deliver Windows malware

Socket uncovered a campaign dubbed Operation Muck and Load built from 222 lure repositories across 190 GitHub accounts.

A malicious Go module posing as a DNS/subdomain scanner (dnsub) embeds a PowerShell loader that fetches an encrypted resolver from public dead drops such as Pastebin, YouTube, and Telegram.

Final payloads include AsyncRAT, Quasar RAT, Vidar, and XMRig. Since January 24, 2026, the actor published over 1,200 versions, 700 of them malicious.