# golang.org/x/crypto@v0.53.0 — Threat Briefing Critical risk — threat briefing for go package golang.org/x/crypto@v0.53.0. Capabilities, risk paths, and what to check. - **Ecosystem:** go - **Latest version:** v0.53.0 ## Risk - **Level:** critical - **Summary:** Sensitive file access with network egress — credential exfiltration pattern ## Capability Summary | Capability | Level | |---|---| | install scripts | none | | network access | client | | filesystem | both | | shell execution | none | ## Capabilities ### Execution - CLI binary installation (Go module) [common] ### Other - Code execution at module-load time (Go init) [common] - SSH credential file access [common] - Cryptographic hashing [common] - Encryption/decryption operations [common] - Long encoded payload [common] - Filesystem write to system directory [common] - Filesystem write to temp directory [common] - Filesystem write to user home (outside .config) [common] - Blank import: file imports a package solely for its init() side effects [common] - TestMain invokes side-effecting external calls [common] - Per-file scan budget exceeded (partial analysis) [common] - Unexpected native binary in source [common] ### Environment - Environment variable access [common] ### Filesystem - Filesystem write [common] - Sensitive file access [unusual] ### Network - Network client [common] ## Key Signals - **** - **** ## Maintainer ## Recommended Action Do not install. Review immediately if already in use.