ThreatCluster

Malicious Go Libraries Impersonate Google UUID to Exfiltrate User Data

First seen 7 Dec 2025, 00:47 UTC GbhackersCyberpressCybersecuritynews 27

Article Content

Browse articles
ThreatCluster

A threat actor using the GitHub alias bpoorman has introduced malicious Go libraries that mimic Google's UUID library. These libraries contain a backdoor through a hidden function named Valid, allowing the exfiltration of sensitive user data. Users of affected systems are at risk of data breaches due to this exploit.