Threat reportSupply ChainTL-2026-0164

Malicious Go crypto Module — Rekoobe Linux Backdoor via golang.org/x/crypto Namespace Confusion

highMONITORING

Malicious Go crypto Module (TL-2026-0164), also tracked as xinfeisoft/crypto supply chain attack, is a high-severity supply-chain compromise scored CVSS 8.8, first published 2026-03-02. It is linked to a China-nexus actor with medium confidence, affects Go Ecosystem github.com/xinfeisoft/crypto, maps to 15 MITRE ATT&CK techniques (T1027, T1036.005, T1041), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
8.8/10High
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0164

Threat ID
TL-2026-0164
Also known as
xinfeisoft/crypto supply chain attack
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
MONITORING
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Detection rules
9
Indicators of compromise
16

Malware and tooling in Malicious Go crypto Module

Malware and tooling: Rekoobe

How Malicious Go crypto Module works

A malicious Go module (github.com/xinfeisoft/crypto) impersonates the foundational golang.org/x/crypto library, injecting a backdoor into ssh/terminal/terminal.go that captures passwords, exfiltrates credentials to attacker infrastructure, plants SSH keys for persistent access, and deploys the Rekoobe Linux backdoor.

Socket Security's Threat Research Team uncovered a malicious Go module published as github.com/xinfeisoft/crypto at version v0.15.0, designed to impersonate the legitimate golang.org/x/crypto codebase — one of the Go ecosystem's foundational cryptography libraries maintained by the Go project itself. The module mirrors the full package layout of the legitimate library (acme, argon2, bcrypt, blake2, ssh, etc.) but inserts a backdoor in ssh/terminal/terminal.go, specifically targeting the ReadPassword() helper function.

The attack chain is multi-staged. When a victim application calls ReadPassword() for interactive password prompts (SSH passphrases, database logins, API keys), the backdoored function captures the plaintext secret and writes it to /usr/share/nano/.lock. It then fetches a GitHub-hosted staging URL (raw.githubusercontent.com/xinfeisoft/vue-element-admin/refs/heads/main/public/update.html) to obtain the next-hop C2 address. The captured password is exfiltrated via HTTP POST to the threat actor's endpoint, followed by retrieval and execution of a shell script via /bin/sh.

The downloaded stager (snn50.txt) performs three critical actions: (1) appends a threat actor-controlled SSH RSA public key to /home/ubuntu/.ssh/authorized_keys for persistent access, (2) sets iptables default policies to ACCEPT to weaken host firewall posture, and (3) downloads and executes two additional payloads from img.spoolsv.cc disguised with .mp5 extensions (sss.mp5 and 555.mp5), confirmed as the Rekoobe Linux backdoor. The stager then deletes dropped files to reduce forensic artifacts.

The threat actor's GitHub account (xinfeisoft) hosts four repositories: crypto (the malicious module), vue-element-admin (staging infrastructure hosting the C2 pointer), demo, and feisoft. Commit history shows the vue-element-admin staging pointer was updated from img.spoolsv.net/seed.php to img.spoolsv.cc/seed.php on July 12, 2025, indicating continued operational maintenance months after the module's February 2025 publication.

Rekoobe is a Linux backdoor historically associated with Chinese-origin threat activity, including APT31/Zirconium and broader Winnti cluster operations. It provides persistent remote access, command execution, and has been observed in campaigns targeting government, technology, and cloud infrastructure sectors.

The malicious module was published to pkg.go.dev on February 20, 2025 and remained available through the Go module proxy until Socket reported it. The Go security team subsequently blocked the module, returning 403 SECURITY ERROR responses. The xinfeisoft GitHub account remains active as of the report date. The hardcoded /home/ubuntu path suggests targeting of Ubuntu-based cloud environments (AWS EC2, GCP, Azure instances using default ubuntu accounts).

The module adds github.com/bitfield/script as a dependency — a legitimate Go library for HTTP requests and shell pipelines — providing convenient abstractions for the outbound network activity and command execution embedded in the backdoor. This dependency choice helps the malicious behavior blend into what appears to be ordinary library usage.

MITRE ATT&CK techniques used in TL-2026-0164

stealth

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion

exfiltration

T1041 Exfiltration Over C2 Channel

collection

T1056.004 Credential API Hooking; T1074.001 Local Data Staging

execution

T1059.004 Unix Shell; T1204.002 Malicious File

command-and-control

T1071.001 Web Protocols; T1102.001 Dead Drop Resolver; T1105 Ingress Tool Transfer

persistence

T1098.004 SSH Authorized Keys

initial-access

T1195.001 Compromise Software Dependencies and Development Tools

credential-access

T1552.001 Credentials In Files

defense-impairment

T1686 Disable or Modify System Firewall

Affected products and versions in Malicious Go crypto Module

  • Go Ecosystem — github.com/xinfeisoft/crypto
    Vulnerable versions: v0.15.0
    Fixed in: Blocked by Go module proxy
  • Linux — Ubuntu-based cloud instances
    Vulnerable versions: All versions with default ubuntu account

Remediation for Malicious Go crypto Module

Patches

  • Remove github.com/xinfeisoft/crypto from go.mod and replace with golang.org/x/crypto
  • Go module proxy now blocks the malicious module (403 SECURITY ERROR)

Immediate actions

  • Audit all Go projects for imports of github.com/xinfeisoft/crypto
  • Search go.sum files for github.com/xinfeisoft/crypto v0.15.0
  • Block network traffic to img.spoolsv.cc and img.spoolsv.net at perimeter
  • Check /home/ubuntu/.ssh/authorized_keys for unauthorized SSH keys
  • Inspect /usr/share/nano/.lock for credential artifacts
  • Review iptables rules for unexpected ACCEPT default policies

Workarounds

  • Set GONOSUMDB and GONOSUMCHECK to prevent resolution of unknown module paths
  • Use go mod verify to check module integrity against go.sum
  • Pin golang.org/x/crypto explicitly in go.mod to prevent path confusion

Longer-term hardening

  • Implement Go module verification using GONOSUMCHECK exclusion lists
  • Deploy dependency scanning with Socket Security or similar tools
  • Use GOFLAGS=-mod=vendor to lock dependencies in vendor directory
  • Monitor for namespace confusion attacks on foundational Go libraries
  • Implement least-privilege network policies for build/CI environments
  • Deploy EDR with behavioral detection for curl|sh patterns

Weaknesses (CWE) in Malicious Go crypto Module

CWE-506, CWE-912, CWE-494, CWE-522

Timeline of Malicious Go crypto Module

  • Threat actor creates vue-element-admin repository on GitHub with public/update.html pointing to img.spoolsv.net/seed.php as C2 staging infrastructure.
  • Malicious Go module github.com/xinfeisoft/crypto v0.15.0 published to pkg.go.dev and Go module proxy, impersonating golang.org/x/crypto.
  • Threat actor updates vue-element-admin/public/update.html C2 pointer from img.spoolsv.net/seed.php to img.spoolsv.cc/seed.php, indicating continued operational maintenance.
  • Socket Security confirms malicious module still fetchable from public Go module mirror as of this date — module had been live for nearly 10 months.
  • Socket Security files abuse report requesting action on the xinfeisoft GitHub account. Account remains active as of report publication.
  • Go security team blocks the malicious module on the public Go module proxy, returning 403 SECURITY ERROR responses. Module no longer resolvable through default Go toolchain.
  • Socket Security Threat Research Team publishes analysis of the malicious module, including full kill chain and Rekoobe backdoor confirmation. Source: https://socket.dev/blog/malicious-go-crypto-module-steals-passwords-and-deploys-rekoobe-backdoor
  • As of 2026-05-29, the malicious xinfeisoft/crypto Go module is blocked by the Go proxy (403 SECURITY ERROR), neutralizing the delivery vector (no CVE/KEV applies). However, the xinfeisoft actor (suspected APT31/Winnti) kept its GitHub account and rotating img.spoolsv.cc C2 active, and Rekoobe remains in use, so the threat stays live and warrants monitoring.

Sources cited for Malicious Go crypto Module

Detection coverage for TL-2026-0164

As of 2026-03-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0164 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats