Use of software with malware In github.com/bufferzonecorp/go-stdlib-ext
Description
This package is a malicious packages part of the Go BufferZoneCorp and RubyGems knot-theory clusters. The packages in this cluster steal credentials, set up ssh access and tamper with build/workflow environmetn variables.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component |
|---|---|
go |
Aliases
1. 2.