# Malicious Go crypto Module — Rekoobe Linux Backdoor via golang.org/x/crypto Namespace Confusion

> A malicious Go module (github.com/xinfeisoft/crypto) impersonates the foundational golang.org/x/crypto library, injecting a backdoor into ssh/terminal/terminal.go that captures passwords, exfiltrates credentials to attacker infrastructure, plants SSH keys for persistent access, and deploys the Rekoobe Linux backdoor.

- **Published:** 2026-03-02T07:12:00Z
- **Last reviewed:** 2026-03-02T07:12:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0164
- **ID:** TL-2026-0164
- **Severity:** HIGH (CVSS 8.8)
- **Category:** SUPPLY_CHAIN
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Socket Security's Threat Research Team uncovered a malicious Go module published as github.com/xinfeisoft/crypto at version v0.15.0, designed to impersonate the legitimate golang.org/x/crypto codebase — one of the Go ecosystem's foundational cryptography libraries maintained by the Go project itself. The module mirrors the full package layout of the legitimate library (acme, argon2, bcrypt, blake2, ssh, etc.) but inserts a backdoor in ssh/terminal/terminal.go, specifically targeting the ReadPassword() helper function.

The attack chain is multi-staged. When a victim application calls ReadPassword() for interactive password prompts (SSH passphrases, database logins, API keys), the backdoored function captures the plaintext secret and writes it to /usr/share/nano/.lock. It then fetches a GitHub-hosted staging URL (raw.githubusercontent.com/xinfeisoft/vue-element-admin/refs/heads/main/public/update.html) to obtain the next-hop C2 address. The captured password is exfiltrated via HTTP POST to the threat actor's endpoint, followed by retrieval and execution of a shell script via /bin/sh.

The downloaded stager (snn50.txt) performs three critical actions: (1) appends a threat actor-controlled SSH RSA public key to /home/ubuntu/.ssh/authorized_keys for persistent access, (2) sets iptables default policies to ACCEPT to weaken host firewall posture, and (3) downloads and executes two additional payloads from img.spoolsv.cc disguised with .mp5 extensions (sss.mp5 and 555.mp5), confirmed as the Rekoobe Linux backdoor. The stager then deletes dropped files to reduce forensic artifacts.

The threat actor's GitHub account (xinfeisoft) hosts four repositories: crypto (the malicious module), vue-element-admin (staging infrastructure hosting the C2 pointer), demo, and feisoft. Commit history shows the vue-element-admin staging pointer was updated from img.spoolsv.net/seed.php to img.spoolsv.cc/seed.php on July 12, 2025, indicating continued operational maintenance months after the module's February 2025 publication.

Rekoobe is a Linux backdoor historically associated with Chinese-origin threat activity, including APT31/Zirconium and broader Winnti cluster operations. It provides persistent remote access, command execution, and has been observed in campaigns targeting government, technology, and cloud infrastructure sectors.

The malicious module was published to pkg.go.dev on February 20, 2025 and remained available through the Go module proxy until Socket reported it. The Go security team subsequently blocked the module, returning 403 SECURITY ERROR responses. The xinfeisoft GitHub account remains active as of the report date. The hardcoded /home/ubuntu path suggests targeting of Ubuntu-based cloud environments (AWS EC2, GCP, Azure instances using default ubuntu accounts).

The module adds github.com/bitfield/script as a dependency — a legitimate Go library for HTTP requests and shell pipelines — providing convenient abstractions for the outbound network activity and command execution embedded in the backdoor. This dependency choice helps the malicious behavior blend into what appears to be ordinary library usage.

## MITRE ATT&CK

- T1195.001 Compromise Software Dependencies and Development Tools
- T1059.004 Unix Shell
- T1204.002 Malicious File
- T1098.004 SSH Authorized Keys
- T1036.005 Match Legitimate Resource Name or Location
- T1070.004 File Deletion
- T1686 Disable or Modify System Firewall
- T1027 Obfuscated Files or Information
- T1056.004 Credential API Hooking
- T1552.001 Credentials In Files
- T1074.001 Local Data Staging
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1102.001 Dead Drop Resolver
- T1041 Exfiltration Over C2 Channel

## Sources

- [Socket Security — Malicious Go crypto Module Steals Passwords and Deploys Rekoobe Backdoor](https://socket.dev/blog/malicious-go-crypto-module-steals-passwords-and-deploys-rekoobe-backdoor)
- [Socket Security — Package Analysis: github.com/xinfeisoft/crypto](https://socket.dev/go/package/github.com/xinfeisoft/crypto)
- [GitHub — xinfeisoft/crypto (malicious repository)](https://github.com/xinfeisoft/crypto)
- [GitHub — xinfeisoft/vue-element-admin (staging infrastructure)](https://github.com/xinfeisoft/vue-element-admin)
- [golang.org/x/crypto — Legitimate Go Cryptography Library](https://pkg.go.dev/golang.org/x/crypto)
- [MITRE ATT&CK — Supply Chain Compromise: Compromise Software Dependencies and Development Tools](https://attack.mitre.org/techniques/T1195/001/)
- [Intezer — Rekoobe Linux Backdoor Analysis](https://www.intezer.com/blog/research/rekoobe-a-new-variant-of-the-rekoobe-linux-backdoor/)
- [Go Module Mirror — Security Policy and Malicious Module Blocking](https://proxy.golang.org/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0164
