Mark RadarMARK RADAR
EN
Event File CRYPTO Supply Chain Attacks

Malicious Go Module Poses as Scanner to Spread Crypto Miner, Data Stealer

1 reports · First detected 2026-07-15 · Last active 2026-07-15

Hackers are exploiting developers’ trust in the open-source ecosystem as a new attack vector. Security firm Socket uncovered a malware campaign targeting software engineers through a disguised Go library. A compromised development environment could trigger a broader supply-chain security crisis, putting companies’ confidential source code and user data at severe risk.

Socket disclosed the campaign, dubbed “Muck and Load,” in July 2026. The attackers used a GitHub lure network comprising 222 malicious repositories to trick developers into running a Go module that installed a Monero miner and data-stealing malware. The Go security team has blocked the module, and the malicious infrastructure has been reported to GitHub for action.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR