Summary
Togoder Security scanned the Go package github.com/thrasher-corp/gct-ta@v0.0.0-20200623072738-f2b55b7f9f41 on Oct 5, 2026. An AI review of 9 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Unvalidated network request construction
NPS-98469558E452
Exchange, currency pair, and period values are taken directly from CLI flags and concatenated into the CryptoWatch API URL without validation or sanitization. While this is a CLI tool, an attacker who can influence these inputs could cause requests to unexpected hosts or paths (e.g., path traversal in exchange/pair segments), potentially leading to SSRF-like behavior or unintended API access.
Hardcoded external API endpoint
NPS-C50F8F897DBB
All data retrieval is directed to a hardcoded third-party API (https://api.cryptowat.ch). This is expected functionality but means the tool relies on an external service that could change or be compromised, affecting data integrity.
Insufficient HTTP error status handling
NPS-5F1CA03CF1B0
The code does not check resp.StatusCode after the HTTP request. It proceeds to read and parse the body even for 4xx/5xx responses, which could lead to parsing unexpected content or masking errors from the remote service.
Missing response body size limit
NPS-E585F0F6A731
ioutil.ReadAll is used to read the entire HTTP response body without any size restriction. A malicious or compromised remote server could return an extremely large response, causing memory exhaustion (denial of service).
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| cmd/gct-ta/main.go | medium | The code is a legitimate CLI indicator tool with no malicious exfiltration, credential harvesting, code execution, or backdoor patterns, but it has minor robustness issues such as unvalidated URL inputs and unbounded response reading. |
| indicators/atr.go | safe | Cleared by Jev triage; no further analysis needed |
| indicators/bbands.go | safe | Cleared by Jev triage; no further analysis needed |
| indicators/correlation.go | safe | Cleared by Jev triage; no further analysis needed |
| indicators/indicators.go | safe | Cleared by Jev triage; no further analysis needed |
| indicators/ma.go | safe | Cleared by Jev triage; no further analysis needed |
| indicators/mfi.go | safe | Cleared by Jev triage; no further analysis needed |
| indicators/obv.go | safe | Cleared by Jev triage; no further analysis needed |
| indicators/rsi.go | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is github.com/thrasher-corp/gct-ta safe to use?
No confirmed malware was found in github.com/thrasher-corp/gct-ta@v0.0.0-20200623072738-f2b55b7f9f41, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/thrasher-corp/gct-ta contain malware?
No malware was identified in github.com/thrasher-corp/gct-ta@v0.0.0-20200623072738-f2b55b7f9f41 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/thrasher-corp/gct-ta checked?
Togoder Security downloaded the published Go package and had an AI model read its 9 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/thrasher-corp/gct-ta together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/thrasher-corp/gct-ta@v0.0.0-20200623072738-f2b55b7f9f41, cost nothing.