Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Hisense unveils portable 4K mini projector with triple lasers
    • “We didn’t hear no bell” – German HealthTech startup doctorly kept from insolvency in full acquisition
    • 8 Best Portable Power Stations (2025): Power Capacity, Portability, Camping, and More
    • Buying a Home on a $100K Salary: Here’s What You Can Actually Afford
    • Nvidia Blackwell Reigns Supreme in MLPerf Training Benchmark
    • Landing your First Machine Learning Job: Startup vs Big Tech vs Academia
    • Praga Bohema becomes the fastest pure combustion car around Top Gear track
    • London’s Kiin Bio raises €1.9 million to launch their Virtual Scientist Platform for drug discovery
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Thursday, June 5
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Go Module Mirror served backdoor to devs for 3+ years
    News

    Go Module Mirror served backdoor to devs for 3+ years

    Editor Times FeaturedBy Editor Times FeaturedFebruary 5, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    A mirror proxy Google runs on behalf of builders of the Go programming language pushed a backdoored package deal for greater than three years till Monday, after researchers who noticed the malicious code petitioned for it to be taken down twice.

    The service, referred to as the Go Module Mirror, caches open supply packages accessible on GitHub and elsewhere in order that downloads are quicker and to make sure they’re suitable with the remainder of the Go ecosystem. By default, when somebody makes use of command-line instruments constructed into Go to obtain or set up packages, requests are routed by way of the service. An outline on the positioning says the proxy is offered by the Go group and “run by Google.”

    Caching in

    Since November 2021, the Go Module Mirror has been internet hosting a backdoored model of a extensively used module, safety agency Socket said Monday. The file makes use of “typosquatting,” a way that offers malicious information names much like extensively used reputable ones and vegetation them in fashionable repositories. Within the occasion somebody makes a typo or perhaps a minor variation from the proper title when fetching a file with the command line, they land on the malicious file as an alternative of the one they needed. (An identical typosquatting scheme is frequent with domains, too.)

    The malicious module was named boltdb-go/bolt, a variation of extensively adopted boltdb/bolt, which 8,367 other packages rely upon to run. The malicious package deal first appeared on GitHub. The file there was ultimately reverted again to the reputable model, however by then, the Go Module Mirror had cached the backdoored one and saved it for the following three years.

    “The success of this assault relied on the design of the Go Module Proxy service, which prioritizes caching for efficiency and availability,” Socket researchers wrote. “As soon as a module model is cached, it stays accessible by way of the Go Module Proxy, even when the unique supply is later modified. Whereas this design advantages reputable use circumstances, the menace actor exploited it to persistently distribute malicious code regardless of subsequent modifications to the repository.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    Two certificate authorities booted from the good graces of Chrome

    June 4, 2025

    Meta and Yandex are de-anonymizing Android users’ web browsing identifiers

    June 3, 2025

    AI pioneer Yoshua Bengio launches LawZero, a nonprofit focused on safer AI; LawZero has raised $30M in donations, including from Skype co-founder Jaan Tallinn (Cristina Criddle/Financial Times)

    June 3, 2025

    Aerones, which makes robots that can service wind turbines in about half the time of humans, raised $62M led by Activate Capital and S2G Investments (Virginia Furness/Reuters)

    June 3, 2025

    Broadcom ends business with VMware’s lowest-tier channel partners

    June 2, 2025

    Alphabet offers to spend $500M+ over ten years to rebuild its global compliance structure, in a settlement proposal for an antitrust lawsuit from shareholders (Michael Acton/Financial Times)

    June 2, 2025

    Comments are closed.

    Editors Picks

    Hisense unveils portable 4K mini projector with triple lasers

    June 5, 2025

    “We didn’t hear no bell” – German HealthTech startup doctorly kept from insolvency in full acquisition

    June 5, 2025

    8 Best Portable Power Stations (2025): Power Capacity, Portability, Camping, and More

    June 5, 2025

    Buying a Home on a $100K Salary: Here’s What You Can Actually Afford

    June 5, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    How to Turn a Live Boston Bruins Hockey Broadcast Into a Cartoon

    March 11, 2025

    British army radio-frequency drone disabling weapon

    April 20, 2025

    Best Internet Providers in El Paso, Texas

    June 2, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.