BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious Go Module Hijacks Linux Passwords

Malicious Go Module Impersonates Crypto Library to Steal Secrets and Deploy Rekoobe Backdoor

  • A malicious Go module impersonates a legitimate “golang.org/x/crypto” library to steal secrets.
  • The malware harvests passwords, creates SSH backdoor access, and deploys the Linux backdoor Rekoobe.
  • The Rekoobe backdoor, linked to Chinese nation-state groups like APT31, enables downloading more payloads and executing reverse shells.
  • The Go security team has blocked the malicious package, but researchers warn similar low-effort, high-impact attacks are likely to repeat.

Cybersecurity researchers disclosed on February 27, 2026, that a malicious Go module is harvesting terminal passwords and deploying the persistent Rekoobe Linux backdoor. The module, hosted under a deceptive name, infiltrates victim applications by impersonating legitimate code.

- Advertisement -

Specifically, the fake “github[.]com/xinfeisoft/crypto” module injects malicious code into the “ssh/terminal/terminal.go” file. Consequently, when an application uses the ReadPassword() function, secrets are captured and sent to a remote server.

The campaign then downloads a staging script to create persistent SSH access and loosen firewall rules. Meanwhile, additional payloads disguised with a .mp5 extension are retrieved from an external server.

One payload is a connectivity-testing helper program. However, the second is identified as Rekoobe, a known Linux trojan active since at least 2015.

This backdoor is capable of receiving commands to download payloads, steal files, and execute a reverse shell. As recently as August 2023, Rekoobe has been used by Chinese nation-state groups like APT31.

- Advertisement -

Socket security researcher Kirill Boychenko said, “This activity fits namespace confusion and impersonation of the legitimate golang.org/x/crypto subrepository.” The Go security team has now taken steps to block the malicious package listed on pkg.go.dev.

Boychenko warned similar supply chain attacks are likely to repeat because the pattern is low-effort and high-impact. Defenders should anticipate more attacks targeting credential libraries.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

ShinyHunters Exploit Oracle Zero-Day, Hit Universities

The ShinyHunters cybercrime group exploited a critical zero-day flaw in Oracle PeopleSoft to steal...

OpenAI Mulls AI Price Cuts Amid IPO Race, Tokenmaxxing Boom

OpenAI is contemplating significant price cuts for its AI tokens in anticipation of a...

NIO’s Onvo L60 SUV priced from $26,700, undercuts Tesla

The new Onvo L60 starts at RMB 192,800 ($26,600), undercutting the Tesla Model Y's...

GameStop pledges $300M Bitcoin to Coinbase

GameStop has pledged its entire 4,709 BTC treasury, worth roughly $300 million, to Coinbase...

Traders Bet Big on ETH Despite 44% Price Drop

Ether futures open interest on Binance has reached a new all-time high of 3.7...

Must Read

Top 7 BEST Crypto Trading Bots for Beginners

QUICK NAVIGATIONQuick Look: Top 3 Best Crypto Trading BotsWhat Exactly is a Crypto Trading Bot?How I Chose These Trading BotsTop 7 Crypto Trading Bots...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading