Fake Go DNS scanner spread malware through over 200 GitHub repos — ‘Operation Muck and Load’ has published 700 malicious modules since January
Go derives a pseudo-version from the commit timestamp and hash for any commit that lacks a semantic version tag. Socket attributes the sprawl to the threat actor’s own GitHub Actions workflow, saying its timed commits co…









