SafeDep
Install GitHub App

Summary

Single low confidence YARA rule match. Interacts with login keychain, but insufficient evidence to classify as malware.

Verification Record

No verification record available.

Details

The package golang.org/x/exp matched the YARA rule login_keychain in the file root_darwin.go. The matched pattern suggests the code might interact with the login keychain, specifically looking for login.keychain-db. While this could be indicative of malicious activity aimed at stealing login credentials, the confidence level is low. Without further evidence of malicious intent or behavior, it's difficult to classify this package as malware. The golang.org/x/exp package is an experimental package, and this particular file is part of a testing command, which could explain the interaction with system files. Therefore, based on this single low-confidence evidence, I cannot classify the package as malware.

golang.org/x/exp@v0.0.0-20250813145105-42675adae3e6Clean
Unverified
Analysed at: 12/28/25, 3:19 AM
Source: https://proxy.golang.org/golang.org%2fx%2fexp/@v/v0.0.0-20250813145105-42675adae3e6.zip
SHA256: afda2c12a708ebed33f507a121b60d585d536ec88de2b5c7ce28f0a6918683de
Confidence: Medium