Go Version History Is Now the Lure

The break is not one bad Go module. The attacker is manufacturing version history at scale, so malicious updates blend into normal package churn and escape the usual “spot the suspicious release” check. Socket says Operation Muck and Load now spans 222 lure repositories across 190 accounts. Since January 24, the actor has published more than 1,200 Go pseudo-versions, about 700 marked malicious, by generating timestamped commits that Go turns into believable version bumps. For teams that ingest public packages from Go modules or CI systems, the trust problem is the release trail itself. Cleanup can remove the visible repo, but it does not undo a dependency ecosystem where version history can be fabricated to make malware look routine.

Part of the PlainSec briefing for 2026-07-10

Sources