Summary
- Scope: every module version that entered the public Go module index between July 4 and October 2, 2026: 9,284,587 entries. From them we pulled 15,447 lookalike modules and 8,196 GitHub accounts that published three or more new Go repositories within an hour, then scanned the 1,141 highest-risk modules with our full static pipeline.
- Result: our lanes found no new malware, and the two modules they flagged were false positives. A real campaign was published inside the window and we missed it: Graphalgo, two Go modules on their own domains, discovered by Aikido and listed in OSV on October 2. Both gaps behind the miss are fixed.
- What we did find: of the 4,260 GitHub repositories our watched Go modules depend on most, 13 have been deleted and 176 renamed. One deleted library,
github.com/tyler-smith/go-bip39, generates cryptocurrency wallet seed phrases, has 63 dependents in our data, and its owner name is unclaimed. - What to do: pin
GOPROXY,GOSUMDBandGONOSUMDBin CI, refusedirectfallbacks, treat any dependency that writes to$GITHUB_ENVas hostile, and checkgo.sumagainst the deleted and renamed modules below. Every campaign in this report was discovered by someone else (Socket, Aikido).
Any domain, and a cache that never forgets
A Go module is any repository path, on GitHub or on its own domain, and Google's mirror keeps serving what it has cached so builds don't break. That keeps builds reliable. It also keeps malicious or abandoned code installable after its source is gone.
Graphalgo, outside every lane we ran
In 90 days of new modules our hunters found no new malware. Graphalgo still got through: it lived on its own domains, where our lanes did not look, and its code tripped none of our checks. Both gaps are fixed, and its malicious versions now score 100.
13 deleted, 176 renamed
Popular dependencies keep building after their repositories disappear. The most sensitive, go-bip39, generates wallet seed phrases. Every cached version is clean, but nobody will ever patch it.
The Go risk is not volume. In our data it comes in a few specific shapes, and each one can be checked where code enters your build.
- lookalike names
- throwaway accounts
- vanity domains
- payloads in init()
- tags rewritten after caching
- abandoned repositories
Why Go needs its own playbook
Most supply-chain detection was built for npm and PyPI, where a central registry hosts every package and install scripts are the usual way in. Go works differently, and each difference changes what an attacker does and what a defender has to watch.
The module path is the repository URL
github.com/owner/repo is fetched from that repository. There is no registry account to take over and no name reservation: anyone can publish any path they control, including a copy of a popular project under a new owner.
A public mirror sits in front
proxy.golang.org "aims to cache content in order to avoid breaking builds", and also says it "does not save all modules forever". In practice a version that disappears from GitHub usually stays downloadable.
No install scripts, but init() runs on import
Any package-level init() in an imported library executes during tests, code generation and every binary that links it. That is where Go payloads live.
The index is public
index.golang.org lists every module version the mirror has seen, in order, with a timestamp. It is the closest thing Go has to a firehose, and it is what this report is built on.
Four published campaigns
Socket discovered three of them and Aikido the fourth. The dates are when the OSV records were listed.
boltdb-go
A lookalike of boltdb/bolt. A malicious version was cached by the module mirror and the GitHub tag was later rewritten to clean code, so reviewers saw clean source while go get kept serving the cached payload.
hypert and layout lookalikes
Seven typosquats under throwaway owners. A []string of single characters is indexed into a wget -O - ... | /bin/bash & command and started through exec.Command("/bin/sh", "-c", ...).
Graphalgo
gocommunity.io/orderedbtree and gogets.dev/btreex, on their own domains. A loader in a deprecated/ subpackage unpacks an encrypted blob disguised as btreex.sql or orderedbtree.so and runs a remote access trojan controlled through an Ethereum smart contract (Arbitrum Sepolia) and a Slack bot token.
BufferZoneCorp
A same-day account published 15 repositories in 80 minutes. init() steals credentials, plants an SSH key and rewrites $GITHUB_ENV and $GITHUB_PATH to hijack later CI steps. Our teardown.
How we hunt
Data sources
The module index
Every module version since a cursor, 2,000 per page: 4,643 pages for 90 days. Feeds lookalikes, bursts and the hourly feed.
The module mirror
The exact zip bytes go get receives. Used for static scanning and the tag comparison.
Repositories and accounts
Tag tarballs, repository status (200, 301, 404), owner status and account creation dates.
Our dependency graph
Distinct dependents per Go module among the ~15,700 modules we watch. Decides which names count as popular.
The four hunting lanes
Lookalikes and vanity domains
A new module copying the repository name of one of the 1,913 most depended-on Go modules under another owner, an owner like <owner>-go, or a standard-library path. Since October 2, also every new module on an unfamiliar host: about 2,700 a week from 713 hosts.
Burst accounts
A GitHub owner with three or more new repositories in one hour. Every repository is scanned when the account was 14 days old or younger at the burst, or no longer exists.
Tag drift
For popular github.com modules, the SHA-256 of every .go file and go.mod in the mirror's zip compared with the GitHub tag's current tarball.
Source status
For the 4,260 GitHub repositories with three or more dependents in our data: still there, renamed, or deleted, and is the original owner name unclaimed.
The static checks
Every scanned module goes through 20 checks over the zip. N1 to N10 are priors we designed in advance. The other ten were added after real campaigns scored zero against them: N11 to N17 after BufferZoneCorp, N18 to N20 after Graphalgo.
/crypto/tlsreplace directives, go:generate, embed, cgo flags, test payloads, owner mismatch and similarcurl/wget piped to a shell, from a URL or variable, beside exec.Commandinit() writing GITHUB_ENV/GITHUB_PATH, split literals includedexec.LookPath("go") plus a file named go written beside itinit() starting sh -c <variable> detachedos/exec.sql), or a .so that is not a native binaryScores add up with an anomaly scanner (capped at 60) and a tier credit. 50 notifies an analyst, 80 makes a promotion candidate, and AI triage reviews grey-zone scores before anything is promoted. New modules have one more rule, the payload gate: they are scored only when N1, N10 or N11 to N20 fires, so a fork cannot score on copied tests and binaries alone.
ResultsThe 90-day look-back
Data table
| Lane | No payload signal | Too large | Scored |
|---|---|---|---|
| Bursts from young accounts | 445 | 1 | 2 |
| Bursts from deleted accounts | 653 | 4 | 0 |
| Standard-library impostor paths | 0 | 0 | 33 |
| Owner impersonations | 3 | 0 | 0 |
Lookalikes
15,411 of the 15,447 lookalikes are plain repository-name copies, almost all of them forks: a fork published as a Go module keeps the upstream's repository name. The names copied most are large, much-forked projects, not obvious typosquat targets.
Data table
| Day | Lookalike modules |
|---|---|
| 2026-07-04 | 1 |
| 2026-07-05 | 68 |
| 2026-07-06 | 71 |
| 2026-07-07 | 83 |
| 2026-07-08 | 79 |
| 2026-07-09 | 123 |
| 2026-07-10 | 84 |
| 2026-07-11 | 72 |
| 2026-07-12 | 66 |
| 2026-07-13 | 38 |
| 2026-07-14 | 71 |
| 2026-07-15 | 81 |
| 2026-07-16 | 74 |
| 2026-07-17 | 64 |
| 2026-07-18 | 55 |
| 2026-07-19 | 115 |
| 2026-07-20 | 64 |
| 2026-07-21 | 62 |
| 2026-07-22 | 75 |
| 2026-07-23 | 75 |
| 2026-07-24 | 72 |
| 2026-07-25 | 92 |
| 2026-07-26 | 94 |
| 2026-07-27 | 90 |
| 2026-07-28 | 91 |
| 2026-07-29 | 66 |
| 2026-07-30 | 55 |
| 2026-07-31 | 48 |
| 2026-08-01 | 88 |
| 2026-08-02 | 54 |
| 2026-08-03 | 76 |
| 2026-08-04 | 90 |
| 2026-08-05 | 290 |
| 2026-08-06 | 81 |
| 2026-08-07 | 93 |
| 2026-08-08 | 83 |
| 2026-08-09 | 68 |
| 2026-08-10 | 105 |
| 2026-08-11 | 407 |
| 2026-08-12 | 104 |
| 2026-08-13 | 78 |
| 2026-08-14 | 90 |
| 2026-08-15 | 402 |
| 2026-08-16 | 86 |
| 2026-08-17 | 94 |
| 2026-08-18 | 100 |
| 2026-08-19 | 79 |
| 2026-08-20 | 105 |
| 2026-08-21 | 83 |
| 2026-08-22 | 94 |
| 2026-08-23 | 75 |
| 2026-08-24 | 112 |
| 2026-08-25 | 102 |
| 2026-08-26 | 116 |
| 2026-08-27 | 77 |
| 2026-08-28 | 104 |
| 2026-08-29 | 522 |
| 2026-08-30 | 185 |
| 2026-08-31 | 159 |
| 2026-09-01 | 109 |
| 2026-09-02 | 121 |
| 2026-09-03 | 125 |
| 2026-09-04 | 111 |
| 2026-09-05 | 110 |
| 2026-09-06 | 149 |
| 2026-09-07 | 85 |
| 2026-09-08 | 112 |
| 2026-09-09 | 121 |
| 2026-09-10 | 340 |
| 2026-09-11 | 177 |
| 2026-09-12 | 908 |
| 2026-09-13 | 110 |
| 2026-09-14 | 160 |
| 2026-09-15 | 142 |
| 2026-09-16 | 114 |
| 2026-09-17 | 176 |
| 2026-09-18 | 345 |
| 2026-09-19 | 225 |
| 2026-09-20 | 294 |
| 2026-09-21 | 281 |
| 2026-09-22 | 526 |
| 2026-09-23 | 335 |
| 2026-09-24 | 538 |
| 2026-09-25 | 357 |
| 2026-09-26 | 297 |
| 2026-09-27 | 277 |
| 2026-09-28 | 686 |
| 2026-09-29 | 428 |
| 2026-09-30 | 460 |
| 2026-10-01 | 405 |
| 2026-10-02 | 592 |
Data table
| Week of | Lookalike modules |
|---|---|
| Jun 29 | 69 (partial) |
| Jul 06 | 578 |
| Jul 13 | 498 |
| Jul 20 | 534 |
| Jul 27 | 492 |
| Aug 03 | 781 |
| Aug 10 | 1,272 |
| Aug 17 | 630 |
| Aug 24 | 1,218 |
| Aug 31 | 884 |
| Sep 07 | 1,853 |
| Sep 14 | 1,456 |
| Sep 21 | 2,611 |
| Sep 28 | 2,571 (partial) |
Data table
| Repo name copied | Lookalike modules |
|---|---|
opentelemetry-collector-contrib | 822 |
core | 527 |
prometheus | 427 |
go-sdk | 390 |
websocket | 378 |
termbox-go | 368 |
sdk-go | 310 |
cosmos-sdk | 289 |
go-prompt | 285 |
handlers | 275 |
All legitimate instrumentation
HTTP instrumentation packages such as dd-trace-go/contrib/net/http and opentelemetry-go-contrib/.../otelhttp, and their forks, several under case variants of one owner (DataDog, datadog, DATADOG). GitHub resolves owners case-insensitively; the mirror treats each spelling as a separate module. All scored 30 and none reached an analyst. N1 needs an allowance for contrib paths.
Clean, and on watch
github.com/labstack-go/echo/v5, github.com/labstack-go/echo/v6 and github.com/go-rs/cors carried no payload signal. A name that imitates a well-known owner and stays clean is how a later swap starts, so they stay on watch.
Burst accounts
8,196 owners published three or more new Go repositories within an hour at least once in 90 days. Most are organisations with monorepos split into modules, or developers pushing a batch of projects; 604 published 20 or more in a single hour. Account age is what separates a batch upload from a BufferZoneCorp.
Data table
| New repos in one hour | Owners |
|---|---|
| 3 | 3,264 |
| 4 | 1,240 |
| 5 | 730 |
| 6 | 541 |
| 7 | 367 |
| 8 | 286 |
| 9 | 260 |
| 10 | 180 |
| 11 | 136 |
| 12 | 108 |
| 13 | 94 |
| 14 | 99 |
| 15 | 59 |
| 16 | 60 |
| 17 | 66 |
| 18 | 57 |
| 19 | 45 |
| 20+ | 604 |
Data table
| Account age at burst | Accounts |
|---|---|
| < 1 day | 22 |
| 1-7 days | 18 |
| 8-14 days | 25 |
| 15-30 days | 18 |
| 1-3 months | 99 |
| 3-12 months | 285 |
| 1-3 years | 560 |
| 3-10 years | 3,206 |
| 10+ years | 3,853 |
Of the 8,086 owners we could resolve, 65 were 14 days old or younger when they burst, with 448 repositories between them, and 110 accounts no longer exist, with 657 repositories still in the index. We scanned all 1,105: 1,098 had no payload signal, 5 were too large to fetch, and two young accounts were flagged on N12 by the same file. Both were false positives.
The two modules were forks of the sing-box proxy platform, github.com/oixcloud3rd/sing-box (score 95) and github.com/akari-project/sing-box (score 40). The file was cmd/internal/read_tag/main.go, which is identical in upstream sagernet/sing-box v1.14.2:
It is sing-box's own CI helper: a command-line tool that writes the release version into $GITHUB_ENV when its workflow runs it with -ci. It has an init(), opens $GITHUB_ENV for appending, and so matched N12 exactly. What it is not is a library: a dependency's package main never runs when the module is imported, so it cannot be an import-time payload. N12, N16 and N17 now skip package main files. The same code in a library package still fires, and every campaign above put its payload in a library.
The campaign we missed: Graphalgo
On October 2, OSV listed two Go modules as malicious: gocommunity.io/orderedbtree (first published around August 11) and gogets.dev/btreex (around September 8), part of a campaign Aikido calls Graphalgo, which also reached Terraform providers. Both were published inside our window. Neither appears in our results, for two reasons that are both ours.
Our lanes never looked
Lookalike matching and burst detection both worked on github.com/<owner>/<repo> paths. A module on its own domain matched neither.
Our checks would not have fired
When we ran the malicious versions through the pipeline afterwards, N1 to N17 and the anomaly scanner scored them 0.
The module zips show why. The payload is split so no single file looks like much, and the package tells AI coding assistants and security scanners to look away.
The ignore files exclude ordinary build directories, which makes them look like routine project hygiene, and **/deprecated/, which is where the loader lives. We did not see this AI-assistant and scanner evasion described in Aikido's write-up, so we note it here. gocommunity.io/orderedbtree does the same with a 1 MB orderedbtree.so that is not a native binary. OSV marks every version of both modules as affected; in the versions we examined, orderedbtree v1.0.0 carried none of these files.
Vanity-domain lane
Every new module on a host outside a well-known list: about 2,700 a week from 713 hosts, scored behind the payload gate.
Checks N18 to N20
All four malicious Graphalgo versions we tested now score 100. BufferZoneCorp still scores 95.
0 hits on 2,691 real modules
13 single-signal hits on the first pass (package lists held as strings, ZIP containers such as .npz and .key). After two fixes, none.
Data table
| Module | Before | After |
|---|---|---|
| BufferZoneCorp go-retryablehttp | 0 | 95 |
| Graphalgo btreex v1.2.3 | 0 | 100 |
| Graphalgo orderedbtree v1.3.1 | 0 | 100 |
The CyberXYZ Go proxy has blocked both modules since 07:22 UTC on October 2, when the OSV records entered our data. On October 7, five days after the OSV listing, the public module mirror was still serving all 16 versions of orderedbtree and all 6 of btreex.
Tag drift: the mirror's copy vs the repository
Tag drift is the check for the boltdb-go technique, and a clean baseline is everything: if legitimate modules routinely differ between the mirror and GitHub, the check is useless. They do not. Before going live we compared 36 popular libraries by hand, including aws-sdk-go (2,871 files) and the major-version modules golang-jwt/jwt/v5, go-redis/redis/v8, redis/go-redis/v9 and jackc/pgx/v5. All 36 matched file for file.
Data table
| Outcome | Modules |
|---|---|
| Exact match | 447 |
| No tagged release | 79 |
| Layout not mappable | 28 |
| Network error | 3 |
| Drift | 0 |
The check now cycles through the popular list about every three hours. A drift alert goes to an analyst with the changed, proxy-only and tag-only file lists and a link to the tag. A maintainer moving a tag after release is the likeliest benign cause, and worth knowing about in its own right: the mirror keeps serving the old bytes to everyone.
Abandoned codeWhat lives only in Google's cache
The source-status sweep asked a simple question of the 4,260 GitHub repositories with three or more dependents among the Go modules we watch: does the repository still exist? 4,068 answered normally.
Data table
| Status | Repositories |
|---|---|
| Renamed, new owner | 160 |
| Renamed, same owner | 16 |
| Repository deleted | 13 |
| Old owner name free | 2 |
| No answer (504) | 3 |
| Healthy (200) | 4,068 |
A rename is mostly harmless: GitHub redirects the old URL, so go get keeps working. It becomes a risk when the old owner name is free, because whoever registers it can create a repository at the old path and publish new versions to anyone who runs go get -u. GitHub retires the namespace of any open-source project that had more than 100 clones in the week before its owner was renamed or deleted, so popular projects are usually protected. From the outside there is no way to tell which are, short of trying to register the name, which we did not do.
Data table
| Old path | Dependents | Now |
|---|---|---|
github.com/imdario/mergo | 586 | darccio |
github.com/uber/jaeger-client-go | 516 | jaegertracing |
github.com/uber/jaeger-lib | 499 | jaegertracing |
github.com/docker/docker | 454 | moby |
github.com/docker/distribution | 279 | distribution |
github.com/envoyproxy/protoc-gen-validate | 230 | bufbuild |
github.com/go-redis/redis | 158 | redis |
github.com/armon/go-metrics | 156 | hashicorp |
github.com/tetratelabs/wazero | 85 | wazero |
github.com/googleapis/gnostic | 83 | google |
Thirteen repositories are gone. Twelve of their owners still exist, so the path cannot be reclaimed by someone else, but no fixes will ever ship from it.
Data table
| Module (repo deleted) | Dependents in our data | Owner name |
|---|---|---|
github.com/tyler-smith/go-bip39 | 63 | free |
github.com/caarlos0/go-shellwords | 30 | still registered |
github.com/tdakkota/asciicheck | 29 | still registered |
github.com/gdexlab/go-render | 7 | still registered |
github.com/antinvestor/apis | 7 | still registered |
github.com/neverlee/keymutex | 7 | still registered |
github.com/pivotal-cf/paraphernalia | 4 | still registered |
github.com/micro/cli | 4 | still registered |
github.com/confluentinc/bincover | 3 | still registered |
github.com/blend/go-sdk | 3 | still registered |
github.com/signalfx/signalfx-agent | 3 | still registered |
github.com/Snawoot/go-http-digest-auth-client | 3 | still registered |
github.com/Soontao/goHttpDigestClient | 3 | still registered |
github.com/tyler-smith/go-bip39
go-bip39 is a BIP-39 implementation: it turns entropy into the mnemonic seed phrases that cryptocurrency wallets are restored from. Both the repository and the tyler-smith account have been deleted. The module mirror still serves its tagged versions (latest v1.1.0, October 2020) and a pseudo-version for the last commit, made on 2024-08-17. Projects that resolve modules without the mirror have already hit the deletion: the Prysm Ethereum client's issue #15997 is titled "github.com/tyler-smith/go-bip39 is gone", and others have moved to github.com/cosmos/go-bip39, a fork used by the Cosmos SDK. It is not a drop-in: its v1.0.0 lacks SetWordList, GetWordList, GetWordIndex and EntropyFromMnemonic, and its last commit was in December 2020. Code that only creates and validates English mnemonics and derives seeds can switch; anything else needs a closer look, or a vendored copy of the original.
We checked the cached code before writing about it. The 2024 commit is a normal maintainer update: entropy comes from crypto/rand, there are no network or exec imports, and our scanner finds nothing. Nothing indicates the module has been compromised. The exposure is forward-looking: the owner name is unclaimed, so if GitHub did not retire the namespace, someone could recreate the repository and publish new versions of a library that generates wallet keys. Given how widely it was used, retirement is the likely outcome, but it cannot be confirmed from the outside.
Since October 2, CyberXYZ flags it at install time. The check never blocks; it tells the developer what happened and what to use instead:
What we got wrong
A report that only lists hits hides how much tuning a detector needs. These are the misses and false positives from building and running this pipeline, all between September 30 and October 2.
Data table
| Issue | Before | After |
|---|---|---|
| Fork lookalikes at notify per week | 18 | 0 |
| N18-N20 hits on calibration corpus | 13 | 0 |
| sing-box CI helper on N12 | 2 | 0 |
| Issue | Measured | Change | Status |
|---|---|---|---|
| N1 to N10 missed a real campaign | A live BufferZoneCorp module scored 0 | N11 to N17 added; it now scores 95 | fixed |
| Graphalgo: lanes and checks | Vanity domains bypassed both lanes; N1 to N17 scored the payload 0 | Vanity lane and N18 to N20; malicious versions score 100 | fixed |
| New checks on real code | 2,691 modules: 19 single-signal hits, 0 at notify | All reviewed and benign; N11, N14 and N17 tightened | fixed |
| Forks of large projects | 18 at notify or above in one week without the gate | Payload gate for new modules: 0 on the same week | fixed |
| N19 and N20 first pass | 13 single-signal hits on the calibration corpus | Imports only for N19; ZIPs flagged only under text names for N20 | fixed |
CI helpers in package main | 2 sing-box forks flagged on N12 | Import-time checks skip package main | fixed |
Instrumentation contrib paths | 33 of 33 stdlib-impostor hits benign (score 30) | Allow known instrumentation path shapes | tuning |
| AI triage context | 2 of 126 day-one verdicts called github.com/apache/kafka unofficial | Prompt gets context on +incompatible modules; score stayed below notify | tuning |
Indicators and hunting signatures
From the published campaigns above: Socket's and Aikido's discoveries, BufferZoneCorp details from our teardown, Graphalgo file details from the module zips. Defanged.
| Type | Indicator | Context |
|---|---|---|
| Graphalgo · MAL-2026-17453, 17454 | ||
| Modules | gocommunity.io/orderedbtree, gogets.dev/btreex | Domains gocommunity[.]io, gogets[.]dev |
| Files | btreex.sql (ZIP), orderedbtree.so (not ELF), deprecated/node.go | Encrypted payload and loader |
| Evasion | **/deprecated/ in .cursorignore, .aiexclude, .snyk, .hacktron/rules.md | Tells AI assistants and scanners to skip the loader directory |
| Command channel | Ethereum smart contract on Arbitrum Sepolia; Slack bot token | RAT dead drop and second channel (per the OSV records) |
| BufferZoneCorp · MAL-2026-3620 to 3636 | ||
| GitHub account | github[.]com/BufferZoneCorp | 10 Go modules; repositories still live on 2026-10-07 |
| Collector | hxxps://webhook[.]site/49c21843-c27c-4a1b-b1f6-037c3998055f | Exfiltration endpoint |
| SSH key comment | deploy@buildserver | Appended to ~/.ssh/authorized_keys by go-stdlib-ext |
| CI environment | GONOSUMDB=*, GONOSUMCHECK=*, GOSUMDB=off, an unknown GOPROXY | Written to $GITHUB_ENV by a dependency, not your workflow |
| boltdb-go and hypert / layout · MAL-2025-2544 to 2551 | ||
| Module | github.com/boltdb-go/bolt | Cache-persistent backdoor |
| Modules | github.com/{belatedplanet,shadowybulk,shallowmulti,thankfulmai}/hypert | Typosquat loaders |
| Modules | github.com/{ornatedoctrin,utilizedsun,vainreboot}/layout | Typosquat loaders |
Hunting the index yourself
Everything in this report can be reproduced from public endpoints. Three starting points:
Recommendations for Go teams
Check go.sum
Search for the deleted and renamed modules above, the campaign modules and BufferZoneCorp. For github.com/tyler-smith/go-bip39, vendor the cached v1.1.0 or move to a fork such as github.com/cosmos/go-bip39 after checking it covers the functions you call. Update renamed imports (imdario/mergo to dario.cat/mergo is the most common).
Pin the toolchain settings
Set GOPROXY, GOSUMDB, GONOSUMDB and GOFLAGS=-mod=readonly at the job level and again in the build step, so a dependency cannot change them through $GITHUB_ENV. No ,direct in CI. Least-privilege GITHUB_TOKEN.
Read the risky shapes
Treat a library that references GITHUB_ENV, authorized_keys or exec.LookPath("go") as hostile until proven otherwise, and read any dependency that ships its own .cursorignore, .aiexclude or .snyk.
Check at the cache
The mirror keeps builds working and also keeps bad bytes available. Put a check in front of it that knows which versions are malicious, which repositories are gone, and when a cached copy no longer matches its tag.
What CyberXYZ runs, and what it does not
Hunting
New lookalike, vanity-domain and burst-account modules from the index, a slice of the proxy-vs-tag check and the source-status sweep, on the Detection page for our analysts, with AI triage on grey-zone scores. Day one: 126 triage verdicts for $0.61.
Blocking and alerts
The CyberXYZ Go module proxy, CLI and VS Code extension block known-malicious Go releases from the date each campaign entered our data (April 30 for boltdb-go and most hypert / layout modules, May 14 for BufferZoneCorp, October 2 for Graphalgo) and alert on orphaned source repositories. The alert never blocks.
Known limits
Code fetched with GOPROXY=direct or copied into another module, and anything published and removed between two hourly runs. We do not run a RubyGems proxy.
Supply-chain risk analysis
Mapped to MITRE ATT&CK:
References
- CyberXYZBufferZoneCorp: Go modules and Ruby gems that hijack your CI
- CyberXYZPackage checker (install-time verdicts for Go, npm, PyPI and NuGet)
- SocketMalicious package exploits Go module proxy caching for persistence (boltdb-go)
- SocketTyposquatted Go packages deliver malware loader (hypert, layout)
- SocketMalicious Ruby Gems and Go Modules Steal Secrets and Poison CI (BufferZoneCorp)
- AikidoGraphalgo campaign spreads to Terraform providers and Go modules
- OSVMAL-2026-17453, MAL-2026-17454, MAL-2025-2545, MAL-2025-2544, MAL-2026-3622
- Goproxy.golang.org FAQ (caching behaviour) and index.golang.org
- GitHubNew tools for open source maintainers (popular repository namespace retirement)
- PrysmIssue #15997: github.com/tyler-smith/go-bip39 is gone
- MITRET1195.001 Compromise Software Dependencies and Development Tools