Rogue Go Module Doubles as Fast SSH Brute-Forcer, Sends Stolen Passwords via Telegram

Socket’s Threat Research Team has uncovered a deceptive Go module named golang-random-ip-ssh-bruteforce, which masquerades as an efficient SSH brute-forcing tool but secretly exfiltrates stolen credentials to its creator. Published on June 24, 2022, this package remains active on the Go Module ecosystem and GitHub, despite efforts to petition for its removal and the suspension of […]

The post Rogue Go Module Doubles as Fast SSH Brute-Forcer, Sends Stolen Passwords via Telegram appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: