Found a group of malicious Go projects injected with trojan

I accidentally discovered malicious programs in the Go ecosystem that impersonate legitimate tools such as the linter ldez/usetesting, the HCL editor go.mercari.io/hcledit, the official MailerSend Go SDK mailersend/mailersend-go, and many more. These programs are not very popular but are still used by some developers. By the time I wrote this article, I had reported the malicious repositories to GitHub support, and most of them have been deleted.

VirusTotal scan results for the trojan `f0eee999`
[Read More]

Fix: no Go 1.15 binary for darwin/arm64 on Apple M1

If you use an Apple Silicon (M1) Mac, you will hit an issue when downloading Go 1.15 or earlier via the dl tool.

Here is the solution:

$ GOARCH=amd64; go run golang.org/dl/go1.15@latest download
$ go install golang.org/dl/go1.15@latest
$ go1.15 version
go version go1.15 darwin/amd64
[Read More]
go  arm64  macos