Malicious Go Module Targets Developers with Credential Theft and Rekoobe Backdoor

Malicious Go Module Targets Developers with Credential Theft and Rekoobe Backdoor

First seen 1 Mar 2026, 20:09 UTC CybersecuritynewsRescanaScworldCyberpress 31.2

Article Content

Browse articles
ThreatCluster

A supply chain attack has been identified involving a malicious Go module, github.com/xinfeisoft/crypto, which impersonates the legitimate golang.org/x/crypto library. This module is designed to exfiltrate sensitive credentials and deploy the Rekoobe Linux backdoor, affecting developers using Go in their environments. The attack utilizes namespace confusion and multi-stage payload delivery techniques.

Timeline

2026-02-27
Malicious Go module discovered mimicking trusted library
2026-03-01
Detailed report published on the attack and its techniques