HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

222 GitHub Repositories Distribute Malicious Go Packages in Coordinated Supply‑Chain Attack

Researchers uncovered 222 GitHub repos that host fake Go modules delivering loaders, stealers, RATs, and cryptominers. The operation shows how third‑party code can become a malware conduit, underscoring the need for SOC 2‑aligned vendor‑risk monitoring.

LiveThreat™ Intelligence · 📅 July 10, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
securityaffairs.com

222 GitHub Repositories Used to Distribute Malicious Go Packages

What Happened — Researchers identified a coordinated operation that created 222 GitHub repositories (across 190 accounts) to host fake Go modules. The modules masquerade as legitimate utilities but, when imported, execute hidden PowerShell loaders that deliver trojan loaders, infostealers (Vidar), spyware, and Monero cryptominers.

Why It Matters for Compliance & Audit Readiness

  • The campaign illustrates a supply‑chain risk where third‑party code can become a vector for malware—exactly the scenario SOC 2 vendor‑management controls are designed to detect and document.
  • Continuous monitoring of open‑source dependencies provides audit‑ready evidence that your organization performed due‑diligence on third‑party assets.
  • Mapping this threat to the SOC 2 CC 6.2 (Third‑Party Risk Management) control helps demonstrate a defensible posture during audits.

Who Is Affected — Software developers, SaaS providers, CI/CD platform operators, and any organization that consumes Go packages from public repositories.

Recommended Actions

  • Inventory all third‑party Go modules in use and compare against a trusted SBOM.
  • Deploy automated tooling that scans public package registries for known malicious signatures and anomalous publishing patterns (e.g., excessive version churn).
  • Document the monitoring process and retain logs as SOC 2 evidence of vendor‑risk oversight.

Technical Notes

  • Attack vector: malicious Go packages that invoke PowerShell with -ExecutionPolicy Bypass and hidden windows, then download and decode additional payloads from muckcoding.com.
  • Payloads include Vidar infostealer, XMRig cryptominer, and custom RAT loaders.
  • The actors used GitHub Actions to generate >1,200 releases, fabricating “active development” to evade casual review.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/195101/security/222-github-repositories-linked-to-fake-go-package-malware-operation.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →