logo

Malicious Go Packages Mimic as Google’s UUID Library to Exfiltrate Sensitive Data

ID: 1c947cbb-0ae6-5fda-af6f-06073025976c

STIX ID: report--1c947cbb-0ae6-5fda-af6f-06073025976c

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2025-12-08

Date Updated: 2026-04-21

Author: Abinaya

...
...

Security researchers uncovered a years‑long supply-chain typosquatting campaign targeting Go developers: two malicious packages (github.com/bpoorman/uuid and github.com/bpoorman/uid) impersonated popular UUID libraries and contained a backdoor Valid function that encrypts and silently exfiltrates input data to dpaste.com with a hardcoded API token; the packages persisted since May 2021 and were still accessible via pkg.go.dev or public mirrors, prompting recommendations to audit go.mod and verify imports.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.