Multiple low confidence YARA matches found, but no strong evidence to classify package as malware. Likely false positives.
No verification record available.
The package golang.org/x/net version 0.47.0 has multiple YARA rule matches, but all of them are of low confidence. The matches include hardcoded_analytics, foreign_object_script, hardcoded_ip_port, js_hex_obfuscation, possible_dropper, and very_high_entropy. These rules can have legitimate use cases, especially in test data, documentation, and build-related files. The presence of a Dockerfile and test data files makes the possible_dropper and foreign_object_script matches less suspicious. Therefore, there is no strong evidence to classify this package as malware.