Go Module Mirror served backdoor to devs for 3+ years
image via Ars Technica
February 5, 2025, 12:25 PM
- •A mirror proxy Google runs on behalf of developers of the Go programming language pushed a backdoored package for more than three years until Monday, after researchers who spotted the malicious code petitioned for it to be taken down twice.
- •The malicious module was named boltdb-go/bolt, a variation of widely adopted boltdb/bolt, which 8,367 other packages depend on to run.
- •The backdoor snuck into the module, constructed a hidden IP address and port, and connected to an attacker-controlled server. It would then execute whatever commands the remote server issued.
Google's Go Module Mirror has been hosting a backdoored version of a widely used module for more than three years. The malicious module was named boltdb-go/bolt, a variation of widely adopted boltdb/bolt, which 8,367 other packages depend on to run. The backdoor snuck into the module, constructed a hidden IP address and port, and connected to an attacker-controlled server. It would then execute whatever commands the remote server issued.
Entities Mentioned
Socket
Topics Covered
Biz & ITSecuritygoopen sourcerepositoriessupply chain attack
Comments (0)
No comments yet.