Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Fortnite Chapter 6 All Shadow Quests Quests in season 3 – disastrous

    June 8, 2025

    Scientists discovered the heaviest proton-emergent nucleus after nearly 30 years.

    June 8, 2025

    New Mirai Botnet infected TBK DVR device through command injection flour

    June 8, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Linux wiper malware is hidden in malicious Go module on github
    Security

    Linux wiper malware is hidden in malicious Go module on github

    PineapplesUpdateBy PineapplesUpdateMay 6, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Linux wiper malware is hidden in malicious Go module on github
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Linux wiper malware is hidden in malicious Go module on github

    A supply-chain attack targets the Linux server, which targets the disc-wiping malware hidden in the Gold Module published on the zethab.

    The expedition was detected last month and included “highly objected codes” to retrieve and execute the remote payload.

    Full disk destruction

    This attack is specifically designed for Linux -based server and developer environment, as a destructive payload – a bash script name done.sh.shA ‘DD’ command runs for the file-wiping activity.

    In addition, the payload is verified that it moves in a linux environment (Runtime.goos == “Linux”) Before trying to execute.

    An analysis of the supply-chain security company socket shows that the command overwrite with zero with every bite of the data, causing irreversible data loss and system failure.

    The target is primary storage volume, /Dev/SDAIt holds important system data, user files, databases and configurations.

    “By populating the entire disk with zero, the script file system structure, operating system and all user data completely destroys, provides the system unbootable and unattainable” – – – – – – – – – – – – – – Socket

    Researchers discovered the attack in April and identified three Go modules on GITHUB, which has since been removed from the stage:

    • github (.) com/truthfulpharm/prototransform
    • github (.) com/blancloggia/go-mcp
    • github (.) com/steelpoor/tlsproxy

    All three modules have an obfacted code that decodes in the command that uses ‘WGET’ to download malicious data-wiping scripts (/bin/bin or/bin/SH).

    According to socket researchers, the payload is executed immediately after download, “almost no time for reaction or recovery.”

    The malicious GO module has applied legal projects to convert the message data to convert message data to convert message data for various forms (prototransform), a GO implementation of model reference protocol (GO-MCP), and TLS Proxy Tools that TCP and HTTP server (TLSPROXY).

    Researchers at the socket have warned that the minimum risk for analyzed disastrous modules can also greatly affect the full data loss.

    Due to the decentralized nature of the GO ecosystem that lacks proper investigation, the package of various developers may have the same or similar names.

    The attackers can take advantage of this to take advantage of this that appears valid and wait for developers to integrate malicious code in their projects.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    Github hidden Linux malicious Malware module wiper
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleOne of our favorite foam mattress toppers is 25% discount for weeks
    Next Article A couple’s small business is a multimilian-dollar success
    PineapplesUpdate
    • Website

    Related Posts

    Security

    New Mirai Botnet infected TBK DVR device through command injection flour

    June 8, 2025
    Security

    Remove project directors presented as malicious NPM package utilities

    June 8, 2025
    Security

    Supply series attacks Glustac NPM package with 960K weekly download

    June 7, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025602 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025542 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025473 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    How to hack a phone: 7 general attack methods explained

    May 16, 20250 Views

    Israel arrested the new suspect behind the Nomad Bridge $ 190M Crypto Hack

    May 17, 20250 Views

    Bangi Marathon confirms the use of stolen art assets in alpha

    May 17, 20250 Views
    Our Picks

    Fortnite Chapter 6 All Shadow Quests Quests in season 3 – disastrous

    June 8, 2025

    Scientists discovered the heaviest proton-emergent nucleus after nearly 30 years.

    June 8, 2025

    New Mirai Botnet infected TBK DVR device through command injection flour

    June 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.