# Fake Go DNS scanner spread malware through over 200 GitHub repos — 'Operation Muck and Load' has published 700 malicious modules since January

> Supply-chain security firm Socket has published research findings describing a Go module that posed as a DNS and subdomain scanner while acting as a first-stage Windows malware loader.

- **Source:** [Tom's Hardware](https://www.tomshardware.com/tech-industry/cyber-security/fake-go-dns-scanner-published-700-malicious-versions-before-researchers-traced-it-to-222-github-repos?utm_source=gearopen.com&utm_medium=referral&utm_campaign=feed&utm_content=6a5234641277eb86c5e1de96)
- **Published:** 2026-07-11
- **Category:** Gaming
- **Tags:** #windows
- **Canonical:** http://localhost:4321/a/6a5234641277eb86c5e1de96

---

_GearOpen's distilled summary. The full original article is published at Tom's Hardware (source link above); GearOpen does not republish the source's full text._
