Malicious Go Packages Mimic as Google’s UUID Library to Exfiltrate Sensitive Data

Security researchers have uncovered a long-running supply chain attack targeting the Go programming community. The Socket Threat Research Team recently identified two malicious packages. github.com/bpoorman/uuid and github.com/bpoorman/uid. That has been silently stealing data from unsuspecting developers for years. The attack relies on a technique called “typosquatting.” Fake Go Packages Discovered The malicious packages are designed to look […]

The post Malicious Go Packages Mimic as Google’s UUID Library to Exfiltrate Sensitive Data appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: