Malicious Go “crypto” Module Steals Passwords and Deploys Re...
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Socket's Threat Research Team discovered a malicious Go module, github.com/xinfeisoft/crypto, impersonating the legitimate golang.org/x/crypto package. The backdoor was inserted into ssh/terminal/terminal.go's ReadPassword function, which captures passwords, exfiltrates them to attacker-controlled infrastructure, and executes a
•11m read time• From socket.dev
Table of contents
Malicious Module: A Backdoored Clone #The Threat Actor #Linux Stager and Backdoor Delivery Chain #Stage Payloads and Rekoobe Backdoor #Outlook and Recommendations #Indicators of Compromise (IOCs) #MITRE ATT&CK #Sort: