Malicious Go Libraries Impersonate Google UUID to Exfiltrate User Data
First seen 7 Dec 2025, 00:47 UTC
•

•27
Export
Article Content
Browse articles
A threat actor using the GitHub alias bpoorman has introduced malicious Go libraries that mimic Google's UUID library. These libraries contain a backdoor through a hidden function named Valid, allowing the exfiltration of sensitive user data. Users of affected systems are at risk of data breaches due to this exploit.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
Data Breach at University of Phoenix Due to Oracle EBS Zero-Day Exploit
Clop Hackers Exploit Oracle Zero-Day, Breaching Barts Health NHS and Dartmouth Data
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows
Cisco Secure Email Gateway Targeted by Advanced Persistent Threat
Logitech Confirms Data Breach Linked to Clop Extortion Gang