How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories

calendar_today July 8, 2026 person Kirill Boychenko domain socket-dev

Our investigation began with a malicious Go module, github[.]com/kaleidora/dnsub-scanning-tool , that posed as a DNS/subdomain scanner. The module did more than impersonate a developer utility: it exposed a Windows malware-staging chain that used hidden PowerShell execution, public dead-drop resolution, protected archive delivery, and RAT/infostealer deployment. Pivoting from that module revealed the larger finding: a GitHub-based lure network of 222 confirmed repositories across 190 accounts, built to make malicious or deceptive software projects look active, plausible, and recently maintaine

open_in_new Read original post