
Research
/Security Fundamentals
Malicious Go Packages Impersonate Google’s UUID Library and Exfiltrate Data
A pair of typosquatted Go packages posing as Google’s UUID library quietly turn helper functions into encrypted exfiltration channels to a paste site, putting developer and CI data at risk.


