216.73.217.22

Typosquatted Go Packages Deliver Malware Loader Targeting Li...

· Published 04/04/2025 11:47 · Modified 04/04/2025 17:02

Export JSON

Essential information

Published
04/04/2025 11:47
Modified
04/04/2025 17:02
Tags
2025-04-04 elf-malware f0eee999 go-packages linux macos obfuscation supply chain attack typosquatting
Related entities
1 malware, 2 others

Description

A malicious campaign is targeting the Go ecosystem with typosquatted packages that install hidden loader malware on and systems. The threat actor has published at least seven packages impersonating popular Go libraries, using array-based string to hide malicious commands. The packages download and execute remote scripts that install an ELF file named , which exhibits minimal initial malicious behavior. The campaign specifically targets UNIX-like environments, placing developers at risk. Multiple domains and fallback infrastructure suggest a persistent and adaptable threat actor. Developers are advised to implement real-time scanning tools, code audits, and careful dependency management to mitigate the risk of supply chain compromises.

External references