Rescana
Malicious Go Module Targets Developers with Credential Theft and Rekoobe Backdoor
First seen 1 Mar 2026, 20:09 UTC
•


•31.2
Export
Article Content
Browse articles
A supply chain attack has been identified involving a malicious Go module, github.com/xinfeisoft/crypto, which impersonates the legitimate golang.org/x/crypto library. This module is designed to exfiltrate sensitive credentials and deploy the Rekoobe Linux backdoor, affecting developers using Go in their environments. The attack utilizes namespace confusion and multi-stage payload delivery techniques.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-27
Malicious Go module discovered mimicking trusted library
2026-03-01
Detailed report published on the attack and its techniques
More articles in this cluster
Continue Reading
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Operation Highland: Velvet Ant's Decade-Long Espionage Campaign
SHADOW-EARTH-053 Exploits Microsoft Exchange Vulnerabilities in Asia
Storm-1175 Deploys New StormEncryptor Ransomware Targeting N-central Systems