In Operation Muck and Load, over 200 GitHub repositories serve a Go module that leads to Windows malware infections.
Socket traced the module to 222 repos across 190 accounts staging Vidar, RATs, and XMRig miners ...
Risk vector: Package managers like npm, pip, Maven, and Go modules all enable pulling dependencies directly from GitHub repositories instead of official registries. Related:Russian Hackers Exploit ...