Security researchers have uncovered a long-running supply chain attack targeting the Go programming community. The Socket Threat Research Team recently identified two malicious packages. github.com/bpoorman/uuid and github.com/bpoorman/uid. That has been silently stealing data from unsuspecting developers for years. The attack relies on a technique called “typosquatting.” Fake Go Packages Discovered The malicious packages are designed to look […]
The post Malicious Go Packages Mimic as Google’s UUID Library to Exfiltrate Sensitive Data appeared first on Cyber Security News.
Read the original article: