Go Package Backdoor Exploits Module Cache to Create Permanent Backdoors
A malicious package impersonating the legitimate BoltDB database module was discovered in the Go ecosystem, enabling unauthorized remote access to compromised systems. The attack exploited Go Module Mirror's indefinite caching feature to maintain persistent distribution of malicious code, ...
