Socket traced the module to 222 repos across 190 accounts staging Vidar, RATs, and XMRig miners, with encrypted payload locations hidden on Pastebin, Telegram, and YouTube.

In Operation Muck and Load, over 200 GitHub repositories serve a Go module that leads to Windows malware infections.

Socket traced the module to 222 repos across 190 accounts staging Vidar, RATs, and XMRig miners, with encrypted payload locations hidden on Pastebin, Telegram, and YouTube.