CRITICAL Go Malware
Malicious code in github.com/BufferZoneCorp/net-helper (Go)
MAL-2026-3629
Published · Modified
Dependency scanning
Check whether github.com/BufferZoneCorp/net-helper is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: google-open-source-security (a4e4f74e90479d472a307d311d48214827e21cf93ecf9b0b62ff2cb72adb2c9e)
This package is a malicious packages part of the Go BufferZoneCorp and RubyGems knot-theory clusters.
The packages in this cluster steal credentials, set up ssh access and tamper with build/workflow environmetn variables.
Ready to move
Start Securing
Free, no credit card | First findings in minutes