Operation Muck and Load is a malware distribution and supply-chain abuse cluster centered on compromised and attacker-controlled GitHub repositories, malicious GitHub Actions workflows, and staged payload delivery through public dead-drop services. The activity has been linked to hundreds of GitHub repositories and accounts and overlaps with a broader cluster tracked by some researchers as Water Curse; "Muck" has also been used as an alias associated with the same activity. The cluster has used software development ecosystems and repository automation as attack infrastructure rather than merely as lure content. In one prominent pattern, malicious code and workflows were inserted into repositories tied to open-source packages, causing GitHub-hosted runners to execute attacker logic. Those runners downloaded architecture-specific Linux payloads, scanned for exposed cPanel and WebHost Manager instances vulnerable to CVE-2026-41940, exploited the authentication bypass, and harvested credentials and operational secrets from compromised servers. Reported collection objectives included cloud credentials, source-control tokens, API keys, database access material, SSH-related secrets, configuration data, and remote execution results. This demonstrates capabilities spanning reconnaissance, scanning, initial access, privilege abuse after authentication bypass, and large-scale exfiltration. A second well-documented pattern involved a malicious Go module masquerading as a DNS and subdomain scanner while functioning as a first-stage Windows loader. The loader launched hidden PowerShell, used certutil along with layered Base64 and XOR decoding, and dynamically resolved downstream payload locations from public platforms including paste sites, messaging services, social media, document-sharing services, and code-hosting mirrors. Retrieved payloads were packaged in password-protected archives and unpacked into directories made to resemble legitimate software before execution, reflecting deliberate defense evasion and staging tradecraft. Payloads associated with the cluster have included information stealers, loaders, downloaders, droppers, spyware, remote access trojans such as AsyncRAT and Quasar, Remcos-style malware, and XMRig-related Monero miners. Lure themes have included cryptocurrency tools and wallets, payment and automation utilities, messaging bots, and game cheats, indicating broad opportunistic targeting of developers and end users as well as server-side exploitation for credential theft. The actor’s operational hallmarks include abuse of GitHub Actions, force-pushed automated commits, use of reusable workflow patterns across many repositories, dynamic dead-drop resolution for payload retrieval, hidden execution, and credential and secret harvesting for likely follow-on compromise or monetization. The activity is best characterized as an opportunistic financially motivated intrusion cluster focused on credential theft, malware delivery, and related post-compromise monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named campaign abusing a large network of GitHub repositories to distribute Windows malware including stealers, loaders, downloaders, droppers, spyware, RATs, and Monero miners.
Supply-chain campaign abusing Go modules and a large network of GitHub repositories to distribute first-stage Windows malware loaders, leading to RATs, infostealers, downloaders, spyware, and cryptominers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.