logo

Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor

ID: 0eec91a1-34f2-5ef2-becb-f755c25bae2e

STIX ID: report--0eec91a1-34f2-5ef2-becb-f755c25bae2e

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-02-27

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed a supply-chain attack where a malicious Go module impersonating golang.org/x/crypto hooks ReadPassword() to steal terminal-entered passwords, then stages a shell script that installs an SSH key, loosens firewall rules, and downloads additional payloads — including a helper contacting 154.84.63.184:443 and the Rekoobe Linux backdoor (historically associated with APT31); the package was later blocked by the Go security team.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.