logo

Waking the Sleepers: The BufferZoneCorp Campaign Poisoning Ruby and Go Ecosystems

ID: 6b3fa35d-51ac-5c29-8038-fa1ba34fd9d0

STIX ID: report--6b3fa35d-51ac-5c29-8038-fa1ba34fd9d0

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Ddos

...
...

Socket researchers uncovered a coordinated supply‑chain campaign from the GitHub account BufferZoneCorp that published plausible Ruby gems and Go modules which were later weaponized to run at install/init time, exfiltrate developer and CI credentials (SSH keys, AWS/NPM/Gem creds, netrc, GitHub CLI), subvert dependency resolution and CI settings, and establish persistence (unauthorized SSH keys). The report identifies specific malicious package name patterns (knot- prefix, lookalike Go modules), a shared webhook exfiltration endpoint, active Ruby gems as of May 2026, and provides immediate defensive recommendations including rotating exposed credentials, auditing dependencies, verifying GOPROXY/GOSUMDB CI settings, and checking authorized_keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.