Malicious Go Module Poses as Scanner to Spread Crypto Miner, Data Stealer
Hackers are exploiting developers’ trust in the open-source ecosystem as a new attack vector. Security firm Socket uncovered a malware campaign targeting software engineers through a disguised Go library. A compromised development environment could trigger a broader supply-chain security crisis, putting companies’ confidential source code and user data at severe risk.
Socket disclosed the campaign, dubbed “Muck and Load,” in July 2026. The attackers used a GitHub lure network comprising 222 malicious repositories to trick developers into running a Go module that installed a Monero miner and data-stealing malware. The Go security team has blocked the module, and the malicious infrastructure has been reported to GitHub for action.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →