logo

Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor in Developer Environments

ID: a96227ec-3ad1-5535-9bc6-b5ce784c55b1

STIX ID: report--a96227ec-3ad1-5535-9bc6-b5ce784c55b1

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-02-27

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Malicious actors published a backdoored Go cryptography module that hooks ReadPassword to harvest plaintext credentials, exfiltrate them via GitHub Raw-provided endpoints, and retrieve/execute a shell stager that appends SSH keys, adjusts iptables, and deploys a Rekoobe Linux backdoor (payloads sss.mp5 and 555.mp5); the report provides IOCs (github.com/xinfeisoft/crypto, github.com/xinfeisoft, img.spoolsv.cc/.net, IP 154.84.63.184, and payload SHA256s) and recommends treating Go module roots as supply-chain boundaries and detecting behaviors such as writes to /usr/share/nano/.lock, GitHub Raw fetches followed by dynamic POSTs, and curl | sh execution chains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.