cognitive cybersecurity intelligence

News and Analysis

Search

Go Module Mirror served backdoor to devs for 3+ years

Google’s mirror proxy for Go programming language developers promoted a backdoored package for over three years. The service, Go Module Mirror, fastens and verifies downloads’ compatibility. However, since November 2021, a maliciously named file has been hosted on it, potentially misleading developers to download it instead of the intended file. The service had cached the malicious file for three years, leading to its continued availability despite changes to the original source.

Source: arstechnica.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts