// Alert

GitHub threat report

A threat actor has deployed Operation Muck and Load, a network of over 200 malicious GitHub repositories across 190 accounts designed to distribute Windows malware. The campaign uses a deceptive Go module masquerading as a DNS scanning tool to load PowerShell code that fetches and executes malware including spyware, trojans, infostealers, and cryptominers. Since January 2026, the actor has published over 1,200 versions of the package, of which 700 are malicious.

// Get alerts for GitHub