Poisoned Go programming language package lay undetected for 3 years
ID: 3e8841dd-7d87-56a6-9f51-d2e6ca467cad
STIX ID: report--3e8841dd-7d87-56a6-9f51-d2e6ca467cad
Feed Name: The Register (Security)
A typosquatted Go module (github.com/boltdb-go/bolt) contained a backdoor that enabled remote code execution and was cached by the Go Module Mirror for about three years, allowing persistent distribution to developers who accidentally imported the malicious package instead of the legitimate boltdb. The attacker used tag manipulation so manual reviews pointed to the real project while the malicious version remained served; Socket Security reported the package and Google removed it and added it to the Go vulnerability database.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
