A fake Go module posing as golang.org/x/crypto captures terminal passwords, installs SSH persistence, and delivers the Rekoobe Linux backdoor.
While the Windows maker did not attribute the activity to a specific threat actor, the use of VS Code tasks and Vercel ...