---
title: "Malicious Go Module Exposes GitHub Malware Lure Network Span..."
url: https://daily.dev/posts/malicious-go-module-exposes-github-malware-lure-network-span--fqwgrwl88
source_url: https://socket.dev/blog/malicious-go-module-exposes-github-malware-lure-network
type: article
source: "Socket"
published: 2026-07-08T21:58:40.289Z
updated: 2026-07-08T21:59:15.071Z
tags: ["security", "github", "golang", "malware", "powershell"]
reading_time: 17
upvotes: 14
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Malicious Go Module Exposes GitHub Malware Lure Network Span...

**[Socket](https://daily.dev/sources/socketdev)** · 17 min read · 14 upvotes · 0 comments

## Summary

Socket researchers uncovered Operation 'Muck and Load', a malware campaign that began with a malicious Go module impersonating a DNS/subdomain scanner. The module embedded hidden PowerShell execution that downloaded encrypted payloads from public dead-drop services (Pastebin, YouTube, Instagram, Telegram), ultimately deploying AsyncRAT, Quasar, Remcos RATs, Vidar infostealer, and Monero cryptominers via password-protected archives. Pivoting from the initial module revealed a GitHub lure network of 222 confirmed repositories across 190 accounts, all using automated commit-farming GitHub Actions workflows to appear active and legitimate. The repositories targeted users seeking crypto tools, wallet utilities, game cheats, and offensive tooling. At least 14 confirmed malware files were found across the network. The malicious Go module has been blocked from the Go module proxy, and GitHub has been notified. The campaign overlaps with previously reported ischhfd83-linked repository-backdoor activity.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://socket.dev/blog/malicious-go-module-exposes-github-malware-lure-network>

## Similar posts on daily.dev

- [Malicious Go “crypto” Module Steals Passwords and Deploys Re...](https://daily.dev/posts/malicious-go-crypto-module-steals-passwords-and-deploys-re--hubou1zfx) · Socket · 59 upvotes · 2 comments
- [Malicious Ruby Gems and Go Modules Impersonate Developer Too...](https://daily.dev/posts/malicious-ruby-gems-and-go-modules-impersonate-developer-too--iyu63tfzm) · Socket · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#github](https://daily.dev/tags/github), [#golang](https://daily.dev/tags/golang), [#malware](https://daily.dev/tags/malware), [#powershell](https://daily.dev/tags/powershell)

[View this post on daily.dev](https://daily.dev/posts/malicious-go-module-exposes-github-malware-lure-network-span--fqwgrwl88)
