Software Sources A.I CyberSecurity Scoring
Software Sources
Company Information
Website:http://www.software-sources.com
Employees number:23
Number of followers:0
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:software-sources.com
Software Sources Risk Score (AI oriented)
Between 750 and 799
Software SourcesIT Services and IT Consulting
Updated:
04/04/2026
04/04/2026
797/1000
Fair
Baa
Software Sources Global Score (TPRM)
xxxx
Software SourcesIT Services and IT Consulting
Score locked

Software SourcesFair
Current Score
797Baa (FAIR)
01000
1 incidents
-10 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
798
MAY 2026
798
APRIL 2026
797
MARCH 2026
807
Cyber Attack
03 Mar 2026 • Software Sources
GitHub and Organizations using Go modules: Go Crypto Malware Steals Credentials and Deploys Rekoobe Backdoor via Supply Chain Breach
Malicious Go Module Backdoors Systems with Rekoobe, Steals Credentials
797
CRITICAL-10
GITSOF1772540739
Malicious Go Module Backdoors Systems with Rekoobe, Steals Credentials
Security researchers at Socket’s Threat Research Team uncovered a supply-chain attack targeting the Go ecosystem, where a malicious module impersonated the widely trusted golang.org/x/crypto library. Hosted on GitHub as github.com/xinfeisoft/crypto, the backdoored module was designed to steal credentials and deploy the Rekoobe Linux backdoor on compromised systems.
The attack exploited the ReadPassword method in the legitimate ssh/terminal/terminal.go file, silently intercepting passwords as users entered them. Captured credentials were stored locally before being exfiltrated to a remote server controlled by the threat actor. The module also fetched and executed a script from GitHub, which acted as a Linux stager modifying system configurations to establish persistence, weaken security, and download additional payloads.
Among the downloaded files, sss.mp5 and 555.mp5 (disguised as media files) were identified as Rekoobe backdoors. The first payload functioned as a reconnaissance tool, while the second, linked to the APT31 (Zirconium) threat group, established command-and-control (C2) communication over TCP port 443, mimicking legitimate HTTPS traffic. Persistence was further ensured by adding an SSH key to authorized_keys and altering iptables rules to allow unrestricted network traffic.
The attack chain highlights the risks of unvetted dependencies, particularly in cryptographic libraries handling sensitive operations. Organizations using Go modules were advised to audit dependencies, monitor CI pipelines for suspicious changes, and enforce security controls like multi-factor authentication (MFA) to mitigate supply-chain threats.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
807
JANUARY 2026
807
DECEMBER 2025
807
NOVEMBER 2025
807
OCTOBER 2025
807
SEPTEMBER 2025
807
AUGUST 2025
807
JULY 2025
807
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Software Sources ??
What was Software Sources's A.I Rankiteo Cyber Score in May 2026 ??
What was Software Sources's A.I Rankiteo Cyber Score in April 2026 ??
What was Software Sources's A.I Rankiteo Cyber Score in March 2026 ??
What was Software Sources's A.I Rankiteo Cyber Score in February 2026 ??
What was Software Sources's A.I Rankiteo Cyber Score in January 2026 ??
What was Software Sources's A.I Rankiteo Cyber Score in December 2025 ??
What was Software Sources's A.I Rankiteo Cyber Score in November 2025 ??
What was Software Sources's A.I Rankiteo Cyber Score in October 2025 ??
What was Software Sources's A.I Rankiteo Cyber Score in September 2025 ??
What was Software Sources's A.I Rankiteo Cyber Score in August 2025 ??
What was Software Sources's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Software Sources's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Software Sources ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Software Sources's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?