Over 200 Fake GitHub Repositories Caught Secretly Installing Windows Malware

A criminal operation called Muck and Load built a web of 222 phoney code repositories to trick software developers into downloading password-stealing programs, spyware, and cryptominers.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: hundreds of identical pale green folders arranged in a vast dark grid
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Criminals created 222 fake repositories, which are public folders where developers share code, across 190 GitHub accounts to spread Windows malware.
  • Security firm Socket uncovered the campaign, named Operation Muck and Load, and confirmed at least 14 malicious files hidden inside.
  • Since 24 January 2026, the attackers published more than 1,200 versions of a poisoned software package, 700 of which carried malware.
  • Final payloads included AsyncRAT and Quasar RAT (remote-access tools that hand criminals full control of a victim's computer), the Vidar infostealer (software designed to silently copy passwords and banking details), and XMRig (a program that hijacks your computer's processing power to secretly mine cryptocurrency).
  • Dead-drop platforms used to relay instructions included Pastebin, YouTube, Instagram, Google Docs, Telegram, and GitCode.

A criminal group built a network of more than 200 fake code repositories on GitHub, the world's largest platform for sharing software, and used them to quietly install malware on Windows computers. Security company Socket published the findings and named the campaign Operation Muck and Load.

How did the attack actually work?

Developers were tricked into downloading what looked like a useful DNS scanning tool, a program that maps websites and their subdomains. The tool mimicked a legitimate open-source project called dnsub. Hidden inside was a poisoned Go module, a type of reusable code package, that ran a PowerShell command, a built-in Windows scripting tool, before any scanning work began. Excessive blank space buried the command, making it nearly invisible in a casual code review.

That command pulled down further instructions from dead drops: public websites used like secret message boards to pass along criminal instructions without running obvious malware servers. Spreading the instructions across so many platforms made the operation resilient. Blocking one source still left several others standing.

Socket also found that the campaign overlaps with activity previously linked to the email address 'ischhfd83', which was associated with Muck-themed domains.

The final payload was a password-protected archive. It decrypted its own download address, fetched the file and executed the contents, all without any visible sign to the user.

Socket confirmed at least 14 unique malware files across the campaign. The set included AsyncRAT and Quasar RAT, giving an attacker live remote control; Vidar, which copies saved credentials and card details; and XMRig-based cryptominers that drain a computer's performance to generate Monero for the criminals. Our earlier story on fake pirated software ads using the same Vidar-plus-miner combination, published 8 July 2026, shows how reliably attackers reach for this pairing when they want both quick cash and persistent access.

Since 24 January 2026 the attackers published over 1,200 versions of the fake package. Socket says the version flood was almost certainly produced by an automated GitHub Actions workflow generating timestamp commits, not any real engineering work.

If you're a developer who recently added an unfamiliar DNS or subdomain scanning package to a Go project, check your dependency list against Socket's published indicators. Remove anything you didn't consciously vet, and scan affected machines for credential theft.

© 2026 Threat Vectr