Home / Companies / Socket / Blog / Post Details
Content Deep Dive

11 Malicious Go Packages Distribute Obfuscated Remote Payloa...

Blog post from Socket

Post Details
Company
Date Published
Author
Olivia Brown
Word Count
1,094
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

Researchers from Socket have discovered eleven malicious Go packages that use obfuscated loaders to fetch and execute second-stage payloads via command and control (C2) domains, with ten packages still live on the Go Module, and eight identified as typosquats. These packages leverage an index-based string obfuscation routine to silently launch a shell, downloading a bash script on Unix systems or a Windows executable, which gathers host information and reads browser data. Despite some C2 URLs being marked as malicious and no longer live, others remain active, posing a risk to developers and CI systems that import these packages. The decentralized nature of the Go ecosystem complicates distinguishing legitimate packages from malicious ones, emphasizing the need for developers to employ real-time scanning, dependency audits, and strict package management to mitigate the risk of supply chain attacks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.