A cracked malicious version of a Go package lay undetected online for years

May Be Interested In:South Carolina and the 67 teams in the March Madness bracket trying to stop a Gamecocks repeat




  • Someone forked a popular database module and fitted it with malware
  • The malicious fork was then cached and stored indefinitely
  • It was then creatively hidden in plain sight to target Go developers

A software supply chain attack targeting developers on the Go platform was apparently hiding in plain sight for three years to spread malware, experts have warned.

Cybersecurity researchers from Socket Security uncovered and publicly spoke about the campaign, which started back in 2021, when someone took a relatively popular database module called BoltDB on GitHub and forked it. In the fork, they added malicious code, which granted the attacker backdoor access to compromised computers.

share Share facebook pinterest whatsapp x print

Similar Content

Barbara Lewis
Building a Sustainable Home: Energy-Efficient Upgrades for Your HDB Flat – Chart Attack
Spacecraft may need to be dirtier to keep astronauts healthy
Spacecraft may need to be dirtier to keep astronauts healthy
Multiplex generation and single-cell analysis of structural variants in mammalian genomes | Science
Multiplex generation and single-cell analysis of structural variants in mammalian genomes | Science
Australia’s richest 47 make $28 billion in a year
Australia’s richest 47 make $28 billion in a year
Graceland mansion in Memphis, Tennessee. Pic: Reuters
Woman admits trying to defraud Elvis Presley’s family by auctioning off Graceland
Berlin Competition Entry ‘The Blue Trail’ Reveals First Clip, Gabriel Mascaro Talks Ageism in Cinema: ‘Elderly Bodies Are Tied to a Nostalgia For Life’ (EXCLUSIVE)
Berlin Competition Entry ‘The Blue Trail’ Reveals First Clip, Gabriel Mascaro Talks Ageism in Cinema: ‘Elderly Bodies Are Tied to a Nostalgia For Life’ (EXCLUSIVE)
Headline Stories: Global Events in the Spotlight | © 2025 | Daily News