UNCOS

Go Module Mirror served backdoor to devs for 3+ years

Go Module Mirror served backdoor to devs for 3+ years

image via Ars Technica

February 5, 2025, 12:25 PM

  • A mirror proxy Google runs on behalf of developers of the Go programming language pushed a backdoored package for more than three years until Monday, after researchers who spotted the malicious code petitioned for it to be taken down twice.
  • The malicious module was named boltdb-go/bolt, a variation of widely adopted boltdb/bolt, which 8,367 other packages depend on to run.
  • The backdoor snuck into the module, constructed a hidden IP address and port, and connected to an attacker-controlled server. It would then execute whatever commands the remote server issued.

Google's Go Module Mirror has been hosting a backdoored version of a widely used module for more than three years. The malicious module was named boltdb-go/bolt, a variation of widely adopted boltdb/bolt, which 8,367 other packages depend on to run. The backdoor snuck into the module, constructed a hidden IP address and port, and connected to an attacker-controlled server. It would then execute whatever commands the remote server issued.

Read original article

Entities Mentioned

Socket

Topics Covered

Biz & ITSecuritygoopen sourcerepositoriessupply chain attack

Comments (0)

No comments yet.