PkgRadar

Go modules · proxy.golang.org

github.com/su1ph3r/bypassburrito

DNS / OAST exfiltration: matched "dig $("

Why PkgRadar flagged v1.0.1-0.20260407223935-8bbf4087991c

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "dig $(" · github.com/su1ph3r/[email protected]/internal/payloads/embedded/cmdi-blind.yaml
mediumRemote Payloadmatched "curl " · github.com/su1ph3r/[email protected]/cmd/burrito/bypass.go
mediumRemote Payloadmatched "Curl " · github.com/su1ph3r/[email protected]/internal/output/reporter.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.1-0.20260407223935-8bbf4087991cHigh risk572026-06-15
v0.2.0High risk572026-06-15
v0.3.0High risk572026-06-15
v0.3.1High risk572026-06-15
v1.0.0High risk572026-06-15

Block this in CI

PkgRadar gates github.com/su1ph3r/bypassburrito (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/su1ph3r/[email protected]