INTEL_REPORT
SecurityWeek · published 7/10/2026, 8:00:14 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Network of 200 GitHub Repositories Used for Malware Infection A Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware. The post Network of 200 GitHub Repositories Used for Malware Infection appeared first on SecurityWeek . Network of 200 GitHub Repositories Used for Malware Infection - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware & Thr…
https://www.securityweek.com/network-of-200-github-repositories-used-for-malware-infection
sha256:442c3b49d991cef55a10187796edfff5b4f96aa23a0decfb8052e3ea67c8e634
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.