Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Malware - Typosquatted Go Packages Distribute Malware Loader Targeting Linux and macOS
Malware Attacks News & Analysis

Typosquatted Go Packages Distribute Malware Loader Targeting Linux and macOS

Kirsten DoyleBy Kirsten DoyleMarch 6, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Typosquatted
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Researchers from Socket have identified an ongoing campaign involving at least seven typosquatted Go packages. These packages impersonate well-known Go libraries and are designed to deploy loader malware on Linux and macOS systems.  

Typosquatted packages are malicious software components designed to mimic the names of popular, legitimate packages. In the context of Go programming, these packages are created with names that are very similar to widely used Go libraries. The goal is to deceive developers into installing these malicious packages instead of the genuine ones. 

According to Socket: “In February 2025, the threat actor released four malicious packages on the Go Module Mirror that impersonate the legitimate github.com/areknoster/hypert library, a popular tool for testing HTTP API clients. These typosquatted clones – github.com/shallowmulti/hypert, github.com/shadowybulk/hypert, github.com/belatedplanet/hypert, and github.com/thankfulmai/hypert – embed concealed functions to enable remote code execution.” 

Evading Detection, Adapting Rapidly 

The malicious packages contain code that achieves remote code execution by running an obfuscated shell command. This command retrieves and executes a script from a remote server, such as “alturastreet[.]icu,” but only after a delay of about an hour— a delay that likely helps this scourge evade detection by security tools. 

The ultimate goal of these attacks is to install and run executable files that can potentially steal sensitive data or credentials. The use of identical filenames and consistent obfuscation techniques suggests a coordinated effort by the threat actors, who are capable of adapting quickly to maintain their operations. 

One of the packages, github.com/shallowmulti/hypert, appears to target developers specifically in the financial sector. This indicates that the malefactors may be focusing on high-value targets where data breaches could yield significant financial gains. 

The discovery of multiple malicious packages and fallback domains indicates that the threat actors have built an infrastructure designed for longevity. This allows them to pivot and continue their operations even if some domains or repositories are blacklisted or removed. 

This campaign highlights the vulnerability of software supply chains to typosquatting attacks. Developers need to be vigilant when installing packages, and package repositories must implement robust security measures to prevent malicious activities of this nature. 

Managing Software Risk 

  “This typosquatting attack is not a new attack vector; however, it still underscores how important it is to manage software risk and verify modules are legitimate before they are integrated into source code.,” comments Thomas Richards, Principal Consultant, Network and Red Team Practice Director at Black Duck.  

“Verifying packages is usually done by signing them before they are added to a central repository. Any application being developed in Go should be reviewed immediately to be sure the malicious packages are not present and systems have not been compromised.”

Targeting the Financial Sector 

 The real danger, adds J Stephen Kowski, Field CTO at SlashNext, is that these sophisticated attacks target developers in the financial sector through typo squatting – creating packages with names very similar to legitimate ones – which can lead to widespread data theft when the malicious code executes after a deliberate delay.  

Kowski says entities should implement automated scanning tools that can detect typo-squatted packages before installation, verify package integrity through hash validation, and deploy real-time behavioral monitoring to catch suspicious activities even when malware uses delayed execution tactics. “Advanced email security solutions that can identify and block phishing attempts containing links to these malicious packages would provide an additional critical layer of protection.” 

 Threat actors are increasingly targeting macOS, a trend that reflects a strategic shift by attackers who recognize that macOS users often hold privileged positions within organizations, such as developers and executives, making them high-value targets for credential theft and system compromise, says Kowski. “The use of cross-platform languages like Go allows attackers to efficiently target multiple operating systems simultaneously, making it essential for security teams to implement comprehensive protection across all platforms rather than assuming any operating system provides inherent immunity.” 

Particularly Severe for APIs 

Eric Schwake, Director of Cybersecurity Strategy at Salt Security, says the typo-squatting risk is particularly severe for APIs, which frequently act as the gateway to sensitive data and essential systems. “To reduce this threat, organizations need to adopt strong security practices, including thorough dependency management, where the origins of all packages are closely examined and verified before being integrated into any project, especially those that involve APIs.” 

 In addition to managing dependencies, Schwake says a thorough API security strategy is critical. “This involves employing automated security scanning tools to identify suspicious activities and potentially harmful code within API projects, along with performing regular vulnerability evaluations to uncover and rectify vulnerabilities. Educating developers is also vital to equip them with the skills to recognize and sidestep threats such as typosquatting. An established API posture governance program can help institutionalize these initiatives, ensuring security is integrated into every phase of the API lifecycle.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

When PUPs bite: Huntress uncovers “weaponised” adware exposing 25,000+ systems

April 16, 20262 Mins Read

Fake Tech Support Scams Deliver Advanced Command-and-Control Malware

March 5, 20262 Mins Read

Americans Lost Over $20 million in ATM “Jackpotting” Attacks

February 24, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}