[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnkSxF6rCCVPhZ8jiGbooniF6qa7ah0-b6bcZiBrURLQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"32030de7-4ade-49bb-8c4e-30c81b4a92c1","200-fake-github-repos-used-to-spread-malware-via-trojanized-go-module","3c721b76-9bb2-48c1-b046-9d9492aeaa8d","200+ Fake GitHub Repos Used to Spread Malware via Trojanized Go Module","Threat actors abused the trust developers place in open-source platforms like GitHub by creating a large network of convincing repositories hosting malware disguised as legitimate tools. A Go module posing as a DNS scanner silently loaded PowerShell code to deploy spyware, infostealers, and cryptominers onto victim machines. The campaign's use of multiple platforms for encrypted payload hosting made it highly resilient to takedowns. This attack highlights how supply chain trust — the assumption that public code repositories are safe — can be weaponized at scale. Developers and organizations that blindly consume open-source code without vetting are particularly vulnerable to this type of campaign.","**Immediate actions:**\n- Audit all third-party Go modules, npm packages, and open-source dependencies currently in use for signs of obfuscated or unexpected PowerShell execution.\n- Block or alert on unauthorized PowerShell invocations originating from developer tools or build pipelines using endpoint protection policies.\n- Report and flag the identified malicious repositories to GitHub's Trust & Safety team to accelerate takedowns.\n\n**Long-term improvements:**\n- Implement a software composition analysis (SCA) tool in CI\u002FCD pipelines to automatically vet open-source dependencies before they are consumed.\n- Establish an internal, vetted package registry or allowlist of approved open-source modules to prevent direct pulls from untrusted public sources.\n- Train developers to verify repository authenticity, star counts, contributor history, and code content before integrating any external module.\n\n**Detection measures:**\n- Monitor outbound network connections from developer workstations and build servers for calls to uncommon or newly registered domains hosting encrypted payloads.\n- Deploy SIEM rules to detect PowerShell download cradles (e.g., `Invoke-Expression`, `DownloadString`) triggered by non-standard parent processes like Go binaries.\n- Implement file integrity monitoring on developer endpoints to catch unexpected executables or scripts dropped by build-time processes.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management","NIST SP 800-218: Secure Software Development Framework (SSDF) – PW.4 (Reuse Well-Secured Software)","NIST CSF DE.CM-3: Personnel activity is monitored to detect cybersecurity events","NIST CSF ID.SC-3: Suppliers and third-party partners are assessed using defined criteria","SLSA Supply Chain Levels for Software Artifacts – Level 2+ (Provenance requirements)","OWASP Top 10: A06:2021 – Vulnerable and Outdated Components","published","2026-07-10T08:20:27.419957+00:00","2026-07-10T08:20:25.775+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.securityweek.com\u002Fnetwork-of-200-github-repositories-used-for-malware-infection\u002F","network-of-200-github-repositories-used-for-malware-infection-9ad822","Network of 200 GitHub Repositories Used for Malware Infection",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":36,"name":37,"slug":38,"description":39,"color":40},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]