Source |
The Hacker News |
Identifiant |
8646843 |
Date de publication |
2025-02-04 19:46:00 (vue: 2025-02-04 16:08:22) |
Titre |
Malicious Go Package Exploits Module Mirror Caching for Persistent Remote Access |
Texte |
Cybersecurity researchers have called attention to a software supply chain attack targeting the Go ecosystem that involves a malicious package capable of granting the adversary remote access to infected systems.
The package, named github.com/boltdb-go/bolt, is a typosquat of the legitimate BoltDB database module (github.com/boltdb/bolt), per Socket. The malicious version (1.3.1) was published to
Cybersecurity researchers have called attention to a software supply chain attack targeting the Go ecosystem that involves a malicious package capable of granting the adversary remote access to infected systems.
The package, named github.com/boltdb-go/bolt, is a typosquat of the legitimate BoltDB database module (github.com/boltdb/bolt), per Socket. The malicious version (1.3.1) was published to |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
access adversary attack attention boltdb caching called capable chain com/boltdb com/boltdb/bolt cybersecurity database ecosystem exploits github go/bolt granting have infected involves legitimate malicious mirror module named package per persistent published remote researchers socket software supply systems targeting typosquat version |
Tags |
|
Stories |
|
Move |
|