Malicious Go Package Exploits Module Mirror Caching for Persistent Remote Access

Researchers studying cybersecurity have drawn attention to a software supply chain attack that targets the Go ecosystem and uses a malicious package that gives the attacker remote access to compromised systems.

According to Socket, the package github.com/boltdb-go/bolt is a typosquat of the authentic BoltDB database module (github.com/boltdb/bolt). After the malicious version (1.3.1) was posted to GitHub in November 2021, the Go Module Mirror service cached it forever.

According to an investigation by security researcher Kirill Boychenko, the threat actor can execute arbitrary commands on the compromised system after installing the backdoored program read more about Malicious Go Package Exploits Module Mirror Caching for Persistent Remote Access.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *