logo

Malicious Go Crypto Module Steals Passwords and Deploy Rekoobe Backdoor in Developer Environments

ID: 822c1bed-9607-5147-8d45-5678adcc9b5d

STIX ID: report--822c1bed-9607-5147-8d45-5678adcc9b5d

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-02-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A malicious Go module published as github.com/xinfeisoft/crypto mimicked the legitimate golang.org/x/crypto library and backdoored the ReadPassword helper to capture plaintext credentials, write them to /usr/share/nano/.lock, post them to attacker-controlled endpoints, and execute a fetched shell script; the script launched a five-stage Linux stager (snn50.txt) that added an SSH key to /home/ubuntu/.ssh/authorized_keys, weakened iptables policies, and downloaded/executed payloads (sss.mp5 and 555.mp5), with 555.mp5 confirmed as a Rekoobe backdoor communicating to 154.84.63.184:443 — the campaign is tied to supply-chain abuse and has links to APT31 activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.