Cybersecurity researchers have discovered three malicious Go libraries that contain code that downloads malware that can irreparably damage the main disk of a Linux system, rendering it unbootable.
See also: New XorDDoS malware allows creation of DDoS botnets

The package names are as follows:
- github[.]com/truthfulpharm/prototransform
- github[.]com/blankloggia/go-mcp
- github[.]com/steelpoor/tlsproxy
These packages are designed to check if the operating system they are running is Linux and if so, download a second malicious file from a remote server via the wget command . This malicious file is a destructive shell script that erases the entire main disk (“/dev/sda”) by writing zeros, thus preventing the system from rebooting
This revelation comes as several malicious npm packages in the official registry, which contain functions to steal mnemonic seed phrases, cryptocurrency private keys, and extract sensitive data. The list of these packages, which were detected by Socket, Sonatype , and Fortinet, is listed below:
- crypto-encrypt-ts
- react-native-scrollpageviewtest
- bankingbundleserv
- buttonfactoryserv-paypal
- tommyboytesting
- compliancereadserv-paypal
- oauth2-paypal
- paymentapiplatformservice-paypal
- userbridge-paypal
- userrelationship-paypal
Malicious packages targeting cryptocurrency wallets have also been identified in the Python Package Index (PyPI) – specifically web3x and herewalletbot – which have recovery phrase spoofing capabilities. These packages have been downloaded over 6,800 times since their publication in 2024.
See also: Akira's new Linux Ransomware attacks VMware ESXi servers

An additional set of seven PyPI packages were found to be using Gmail's SMTP servers and WebSockets to extract data and execute commands remotely, in an attempt to evade detection. The packages in question have now been removed and are as follows:
- cfc-bsb (2,913 downloads)
- coffin2022 (6,571 downloads)
- coffin-codes-2022 (18,126 downloads)
- coffin-codes-net (6,144 downloads)
- coffin-codes-net2 (6,238 downloads)
- coffin-codes-pro (9,012 downloads)
- coffin-grave (6,544 downloads)
The packages use hardcoded Gmail account credentials to connect to the service's SMTP server and send a message to another Gmail address, notifying them of the successful compromise of the system. They then create a WebSocket connection to establish a two-way communication channel with the attacker.
Malicious actors exploit the trust associated with Gmail domains (“smtp.gmail[.]com”), as well as the fact that corporate proxy servers and endpoint protection systems rarely consider such traffic suspicious — making the attack particularly discreet and reliable.
See also: CISA added Linux kernel vulnerability to KEV List
To reduce the risk of such attacks in the supply chain , developers are advised to:
- They verify the authenticity of packages by checking the publisher's history and linked GitHub repositories,
- They regularly check the dependencies of their projects,
- They enforce strict rules on access to private keys.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
