HomeSecurityMalicious Go Modules Spread Disk-Wiping Linux Malware

Malicious Go Modules Spread Disk-Wiping Linux Malware

Cybersecurity researchers have discovered three malicious Go libraries that contain code that downloads malware that can irreparably damage the main disk of a Linux system, rendering it unbootable.

See also: New XorDDoS malware allows creation of DDoS botnets

Linux GO malware

The package names are as follows:

  • github[.]com/truthfulpharm/prototransform
  • github[.]com/blankloggia/go-mcp
  • github[.]com/steelpoor/tlsproxy

These packages are designed to check if the operating system they are running is Linux and if so, download a second malicious file from a remote server via the wget command . This malicious file is a destructive shell script that erases the entire main disk (“/dev/sda”) by writing zeros, thus preventing the system from rebooting

This revelation comes as several malicious npm packages in the official registry, which contain functions to steal mnemonic seed phrases, cryptocurrency private keys, and extract sensitive data. The list of these packages, which were detected by Socket, Sonatype , and Fortinet, is listed below:

  • crypto-encrypt-ts
  • react-native-scrollpageviewtest
  • bankingbundleserv
  • buttonfactoryserv-paypal
  • tommyboytesting
  • compliancereadserv-paypal
  • oauth2-paypal
  • paymentapiplatformservice-paypal
  • userbridge-paypal
  • userrelationship-paypal

Malicious packages targeting cryptocurrency wallets have also been identified in the Python Package Index (PyPI) – specifically web3x and herewalletbot – which have recovery phrase spoofing capabilities. These packages have been downloaded over 6,800 times since their publication in 2024.

See also: Akira's new Linux Ransomware attacks VMware ESXi servers

Malicious Go Modules Spread Disk-Wiping Linux Malware
Malicious Go Modules Spread Disk-Wiping Linux Malware

An additional set of seven PyPI packages were found to be using Gmail's SMTP servers and WebSockets to extract data and execute commands remotely, in an attempt to evade detection. The packages in question have now been removed and are as follows:

  • cfc-bsb (2,913 downloads)
  • coffin2022 (6,571 downloads)
  • coffin-codes-2022 (18,126 downloads)
  • coffin-codes-net (6,144 downloads)
  • coffin-codes-net2 (6,238 downloads)
  • coffin-codes-pro (9,012 downloads)
  • coffin-grave (6,544 downloads)

The packages use hardcoded Gmail account credentials to connect to the service's SMTP server and send a message to another Gmail address, notifying them of the successful compromise of the system. They then create a WebSocket connection to establish a two-way communication channel with the attacker.

Malicious actors exploit the trust associated with Gmail domains (“smtp.gmail[.]com”), as well as the fact that corporate proxy servers and endpoint protection systems rarely consider such traffic suspicious — making the attack particularly discreet and reliable.

See also: CISA added Linux kernel vulnerability to KEV List

To reduce the risk of such attacks in the supply chain , developers are advised to:

  • They verify the authenticity of packages by checking the publisher's history and linked GitHub repositories,
  • They regularly check the dependencies of their projects,
  • They enforce strict rules on access to private keys.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS