* [Blog](https://www2.paloaltonetworks.com/blog) * [Security Operations](https://www2.paloaltonetworks.com/blog/security-operations/) * [AI and Cybersecurity](https://www2.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/) * Cortex AES Extends Code P... # Cortex AES Extends Code Package Visibility to Go [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fcortex-aes-extends-code-package-visibility-to-go%2F) [](https://twitter.com/share?text=Cortex+AES+Extends+Code+Package+Visibility+to+Go&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fcortex-aes-extends-code-package-visibility-to-go%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fcortex-aes-extends-code-package-visibility-to-go%2F&title=Cortex+AES+Extends+Code+Package+Visibility+to+Go&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www2.paloaltonetworks.com/blog/security-operations/cortex-aes-extends-code-package-visibility-to-go/&ts=markdown) \[\](mailto:?subject=Cortex AES Extends Code Package Visibility to Go) Link copied By [Belle Kriger](https://www.paloaltonetworks.com/blog/author/belle-kriger/?ts=markdown "Posts by Belle Kriger") and [Alice Nguyen](https://www.paloaltonetworks.com/blog/author/alice-nguyen/?ts=markdown "Posts by Alice Nguyen") Oct 07, 2026 5 minutes [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown) [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown) [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown) [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown) [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown) [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [cloud infrastructure security](https://www.paloaltonetworks.com/blog/tag/cloud-infrastructure-security/?ts=markdown) [cloud-native supply chain risk](https://www.paloaltonetworks.com/blog/tag/cloud-native-supply-chain-risk/?ts=markdown) [Cortex AES code packages](https://www.paloaltonetworks.com/blog/tag/cortex-aes-code-packages/?ts=markdown) [endpoint software inventory](https://www.paloaltonetworks.com/blog/tag/endpoint-software-inventory/?ts=markdown) [Go module security](https://www.paloaltonetworks.com/blog/tag/go-module-security/?ts=markdown) [Go retracted modules](https://www.paloaltonetworks.com/blog/tag/go-retracted-modules/?ts=markdown) ### **The Market Shift** Go powers the control plane of cloud-native infrastructure: Docker, Kubernetes, Terraform, and most of the tooling built around them. That means Go modules now sit deep inside the systems that provision, orchestrate, and secure the modern enterprise. As platform, DevOps, and security engineering teams have scaled their use of Go, the language has quietly become as business-critical as the infrastructure it builds. Adversaries already know how to exploit open-source package ecosystems, and Go's module system carries the same structural exposure, but with one important difference. Go's module system introduces distinct supply-chain considerations: replace directives can redirect dependencies to different modules or forks, while retracted versions may remain in use despite being withdrawn by their maintainers. ### **The Gap** Legacy software composition analysis tools and endpoint inventory products were largely built around the most established ecosystems like npm and PyPI. As a result, Go modules installed across endpoints have gone largely unexamined. There's no consistent view of what's installed, who published it, what it can do, or whether it's been quietly retracted or swapped out underneath a build. For organizations whose infrastructure teams live in Go, that's not a minor coverage gap. It's a blind spot sitting directly inside the tooling that runs production infrastructure. ### **Introducing Go support in Cortex AES Code Packages** Cortex AES now continuously discovers Go modules installed on endpoints across the organization, and is available now for both Windows and macOS. Rather than scanning repositories or CI pipelines after the fact, Cortex AES inventories what's actually installed on real endpoints, then enriches every module with vulnerability data, behavioral analysis, and repository health signals. The result is a live, endpoint-grounded view of Go's software supply chain rather than a point-in-time snapshot. ### **Full-Depth Discovery, Built For How Go Works** Every Go module Cortex AES finds gets a complete entry in the Code Packages Inventory. That depth extends into findings unique to how Go's ecosystem is built, not just the risks it shares with other languages. Cortex AES discovers every Go module installed across Windows and macOS endpoints, including publisher, version, and license, and surfaces known vulnerabilities in a module and its declared direct and indirect dependencies using Cortex AES's risk engine. It detects malicious modules and flags modules that reference expired domains, a common precursor to supply-chain hijacking. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/10/word-image-369439-1-1.png) Figure 1. An Inventory List of Go Modules Found by Cortex AES Beyond vulnerabilities, Cortex AES tracks the hygiene of the Go ecosystem itself. It identifies deprecated, unmaintained, and retracted modules before they become the next unpatched CVE, and reveals replaced dependencies where the code that runs doesn't match what the manifest declares. Repository health signals like maintainer type, stars, and last update help separate official releases from single-maintainer risk. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/10/word-image-369439-2-1.png) Figure 2. Domains Identified in Go Module Code with Active External Communications ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/10/word-image-369439-3-1.png) Figure 3. An Overall View of a Go Code Package and Its Risk ### **Built For the Teams Running Your Infrastructure** Go's footprint isn't confined to a single team. Platform engineers, DevOps, and security engineering teams all install and depend on Go modules as part of their daily work, often without a central view of what's accumulating across their endpoints. Historically, that meant security teams either had no visibility into this layer at all, or had to rely on periodic, manual audits that were stale the moment they were run. With Go support in Cortex AES, that friction disappears. Security teams get the same continuous, endpoint visibility into Go that they already have into npm and PyPI. Cortex AES helps surface the malicious module, a retracted dependency, or an unmaintained package the moment it lands on an endpoint. This matters more as infrastructure-as-code and platform engineering practices continue to expand. As organizations lean further into Kubernetes, Terraform, and Go-based internal tooling, the modules powering that infrastructure become as consequential to the software supply chain as any application dependency, and just as capable of introducing risk if left unexamined. ### **Real-World Threats: Malicious Go Modules in the Wild** To understand exactly why continuous endpoint visibility into Go is necessary, consider these two examples of malicious modules designed specifically to exploit developer environments and cloud-native infrastructure: * **The Hidden Dropper (gocommunity.io/orderedbtree):** This module secretly runs malicious code on the victim's machine when specific conditions are met. It presents itself as a B-Tree library and uses several techniques to hide its activity, including removing the files it creates after execution. * **The Impersonator(\[github.com/SUPERC0RE/cobra\](https://github.com/SUPERC0RE/cobra)):** This module secretly steals sensitive information from infected systems. It targets saved browser passwords, login sessions, and cryptocurrency wallet data across Windows, macOS, and Linux, then sends the stolen information to an attacker-controlled server. These aren't theoretical vulnerabilities - they are active supply-chain attacks targeting the very engineers building modern infrastructure. Cortex AES closes this blind spot, giving security teams the ability to instantly flag and neutralize deceptive packages like these the moment they land on an endpoint. **Learn more about Cortex AES** [**here**](https://www.paloaltonetworks.com/cortex/agentic-endpoint-security). *** ** * ** *** ## Related Blogs ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### Identity Meets the SOC: Redefining the Last Perimeter](https://www2.paloaltonetworks.com/blog/security-operations/identity-meets-the-soc-redefining-the-last-perimeter/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### Cortex XDR Scores Perfect 100% in SE Labs 2026 Ransomware Test](https://www2.paloaltonetworks.com/blog/security-operations/cortex-xdr-scores-perfect-100-in-se-labs-2026-ransomware-test/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Cortex XDR is the only Certified Leader in AV-Comparatives EPR 7 years in a row](https://www2.paloaltonetworks.com/blog/security-operations/cortex-xdr-is-the-only-endpoint-security-market-leader-to-be-certified-by-av-comparatives-7-years-in-a-row/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Threat Intelligence](https://www.paloaltonetworks.com/blog/category/threat-intelligence-1/?ts=markdown) [#### How Mythos-Class Models Change Exposure Management](https://www2.paloaltonetworks.com/blog/security-operations/how-mythos-class-models-change-exposure-management/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown) [#### Securing Data in the AI Era: Purpose-Built DLP for the Modern Endpoint](https://www2.paloaltonetworks.com/blog/security-operations/securing-data-in-the-ai-era-purpose-built-dlp-for-the-modern-endpoint/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown) [#### Modernising the SOC: Navigating the Shift to Platformization and Agentic AI](https://www2.paloaltonetworks.com/blog/security-operations/modernising-the-soc-navigating-the-shift-to-platformization-and-agentic-ai/) ### Subscribe to Security Operations Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www2.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * Observability * [Cortex XCOR](https://www.paloaltonetworks.com/cortex/xcor?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense?ts=markdown) * [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown) * [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown) * [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown) * [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language