Security researchers have uncovered a long-running supply chain attack targeting the Go programming community. The Socket Threat Research Team recently identified two malicious packages. github.com/bpoorman/uuid and github.com/bpoorman/uid. That has been silently stealing data from unsuspecting developers for years. The attack relies on…
The post Malicious Go Packages Mimic as Google’s UUID Library to Exfiltrate Sensitive Data appeared first on IT Security News.