⤷ Title: Silent Supply Chain Attack: Malicious Go Typosquat Siphoned Data to Pastebin for Four Years Undetected
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:32:24 +0000
════════════════════════
⌗ Tags: #Malware #AES_CFB #backdoor #data exfiltration #dpaste #Go Package #Go Typosquatting #security #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:32:24 +0000
════════════════════════
⌗ Tags: #Malware #AES_CFB #backdoor #data exfiltration #dpaste #Go Package #Go Typosquatting #security #Supply Chain
Daily CyberSecurity
Silent Supply Chain Attack: Malicious Go Typosquat Siphoned Data to Pastebin for Four Years Undetected
A malicious Go package typosquat (bpoorman/uuid) operated for four years, using a hidden Valid function to silently encrypt and exfiltrate sensitive data to dpaste.com.