logo

Database

Use of software with malware In github.com/bufferzonecorp/go-stdlib-ext

Description

This package is a malicious packages part of the Go BufferZoneCorp and RubyGems knot-theory clusters. The packages in this cluster steal credentials, set up ssh access and tamper with build/workflow environmetn variables.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.