Analyze your own packages withvet GitHub

github.com/clipperhouse/stringish@v0.1.1

Suspicious
Analyzed at:10/28/2025, 4:07:33 PM
Source:https://proxy.golang.org/github.com%2fclipperhouse%2fstringish/@v/v0.1.1.zip
SHA256:b64486091fd9c743a51a025c0c171b0d6f43e5a8fbba799e6d3029f79315621f
Confidence:Medium
Summary

This analysis was performed using vet and SafeDep Cloud Malicious Package Analysis. Integrate with GitHub using vet-action GitHub Action.

Embedded executable with extension mismatch, high entropy, and low project popularity suggest this package is likely malware.

Details

The package contains an embedded executable (utf8.test) which is unusual for a string manipulation library. The file extension mismatch and the high_entropy_trailer YARA rule match further raise suspicion. The project's low popularity and few published versions add to the concern, suggesting potential malicious intent.