Socket researchers uncovered Operation 'Muck and Load', a malware campaign that began with a malicious Go module impersonating a DNS/subdomain scanner. The module embedded hidden PowerShell execution that downloaded encrypted payloads from public dead-drop services (Pastebin, YouTube, Instagram, Telegram), ultimately deploying AsyncRAT, Quasar, Remcos RATs, Vidar infostealer, and Monero cryptominers via password-protected archives. Pivoting from the initial module revealed a GitHub lure network of 222 confirmed repositories across 190 accounts, all using automated commit-farming GitHub Actions workflows to appear active and legitimate. The repositories targeted users seeking crypto tools, wallet utilities, game cheats, and offensive tooling. At least 14 confirmed malware files were found across the network. The malicious Go module has been blocked from the Go module proxy, and GitHub has been notified. The campaign overlaps with previously reported ischhfd83-linked repository-backdoor activity.

17m read timeFrom socket.dev
Post cover image
Table of contents
The Malicious Go Module #PowerShell Loader and Dead-Drop Resolver #AsyncRAT, Quasar, Remcos, and Infostealer Activity #GitHub Infrastructure: A 222-Repository Lure Network #Malware-Bearing GitHub Repositories #Overlap with Previously Reported ischhfd83-Linked Activity #Outlook and Recommendations #MITRE ATT&CK #Indicators of Compromise #
15.9K Impressions