Operation Muck and Load GitHub malware-delivery cluster
Malware Activity
Summary
Hide ▲
Show ▼
Operation Muck and Load has expanded a GitHub repository network into a malware-delivery channel, putting 200 repositories across 190 accounts behind the spread of Windows-based malware. The activity matters because the repositories are not just lures; they also distribute payloads through GitHub release assets and embedded content. The payload mix includes information stealers, loaders, downloaders, droppers, spyware, remote access trojans, and Monero miners.
Related Happenings
FakeGit GitHub lure campaign
Campaign
H score32
First: 20.07.2026 21:23
Last: 20.07.2026 21:23
Sources 1
About this happening:
The FakeGit campaign is a GitHub lure operation using nearly 7,600 malicious repositories to distribute SmartLoader and StealC through copied projects, lookali...
FakeGit GitHub lure campaign
CampaignAbout this happening: The FakeGit campaign is a GitHub lure operation using nearly 7,600 malicious repositories to distribute SmartLoader and StealC through copied projects, lookali...
Latest development: 22.07.2026 01:34
Island said FakeGit expanded into more than 1,400 repositories tied to AI tools, agents, and workflows, while public registries and catalogs surfaced more than 600 skills and MCP server listings linked to the campaign. The lure set used AgentBaiting to increase visibility to AI agents, and controlled tests showed ChatGPT, Gemini, Claude, and Claude Code could surface or clone malicious repositories and download files before stopping.
AsyncAPI malicious npm package supply-chain malware
Malware Activity
H score21
First: 15.07.2026 18:37
Last: 15.07.2026 18:37
Sources 1
About this happening:
Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI malicious npm package supply-chain malware
Malware ActivityAbout this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
North Korean Contagious Interview PolinRider supply-chain campaign
Campaign
H score51
First: 04.07.2026 14:17
Last: 04.07.2026 14:17
Sources 1
About this happening:
The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
North Korean Contagious Interview PolinRider supply-chain campaign
CampaignAbout this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
Mini Shai-Hulud / Miasma / Hades multi-ecosystem supply-chain malware activity
Malware Activity
H score36
First: 26.06.2026 14:05
Last: 26.06.2026 14:05
Sources 1
About this happening:
The Mini Shai-Hulud / Miasma / Hades malware activity added malicious npm releases, GitHub Actions workflow abuse, and a related Go module compromise, increasing t...
Mini Shai-Hulud / Miasma / Hades multi-ecosystem supply-chain malware activity
Malware ActivityAbout this happening: The Mini Shai-Hulud / Miasma / Hades malware activity added malicious npm releases, GitHub Actions workflow abuse, and a related Go module compromise, increasing t...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware Activity
H score13
First: 18.06.2026 18:00
Last: 18.06.2026 18:00
Sources 1
About this happening:
A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware ActivityAbout this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Timeline
-
23.07.2026 14:28 2 articles · 1h ago
Operation Muck and Load abuses 200 GitHub repositories to deliver Windows malware
Initial DisclosureOperation Muck and Load uses a network of 200 GitHub repositories across 190 accounts to deliver Windows-based malware, including information stealers, loaders and downloaders, droppers, spyware, remote access trojans, and Monero cryptocurrency miners. Some of the repositories function as malware-bearing hosts by embedding malicious payloads directly in the source tree or by delivering them through GitHub release assets, and the broader chain can pull a password-protected archive after a PowerShell script queries dead drop sites.
Show sources
- Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers — thehackernews.com — 23.07.2026 14:28
- Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers — thehackernews.com — 23.07.2026 14:28