Summary
Togoder Security scanned the Go package github.com/twitchyliquid64/golang-asm@v0.15.1 on Oct 5, 2026. An AI review of 104 source files produced 3 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 11
Lack of input validation on object file data
NPS-5526BF3FB335
The Reader methods compute offsets and lengths based on the header's Offsets array without validating that they are within the bounds of the provided byte slice. A malicious object file could cause panics (index out of range) or out-of-bounds reads, potentially leading to denial of service or memory corruption.
Potential out-of-bounds read
NPS-9B239EF72029
Several methods use unsafe.Pointer to cast byte slices to structs (e.g., Sym, Reloc, Aux). There is no bounds checking in these casts, which could lead to out-of-bounds reads if the object file is malformed. This is a common pattern in low-level parsers but can be exploited to cause crashes or information disclosure.
File system manipulation / Response file expansion
NPS-F17D43E2A11C
The expandArgs function reads arbitrary files specified by '@filename' command-line arguments using ioutil.ReadFile(s[1:]). This enables an attacker who can influence command-line arguments to cause the tool to read any file readable by the process. While not inherently malicious and matching documented Go toolchain behavior, it is an unusual file-read capability that could be abused for data exfiltration if combined with other flaws.
external process execution
NPS-73ED6E49D2BB
The function IsDWARFEnabledOnAIXLd executes an external linker binary (extld) with the -Wl,-V flag to check its version on AIX. This is a legitimate, narrowly scoped use for DWARF configuration on AIX and does not perform arbitrary command execution or shell injection. No user-controlled input is interpolated into a shell, and no suspicious behavior is present.
Unsafe string construction from read-only memory
NPS-025661200781
The toString function uses unsafe.Pointer to convert a byte slice backed by read-only memory into a string without copying. If the underlying memory is later modified (e.g., via unsafe pointers elsewhere), it could lead to data corruption or security issues. However, the code checks r.readonly before calling it, so the risk is mitigated.
Use of `unsafe` package for performance
NPS-FA52C120820A
The code extensively uses unsafe to reinterpret byte slices as structs and to create strings without copying. While this is typical for performance-critical parsers, it increases the risk of memory safety issues if not carefully audited.
init-time registration
NPS-A9197299A78F
The init() function registers ARM register/opcode formatting handlers with the Go object package. This is normal for Go toolchain libraries and only mutates in-process tables; it performs no network, filesystem, or process operations.
Go init function
NPS-7C1016961F9C
The file contains an init() function that populates a DWARF register mapping table. It only performs local map assignments and makes no network, file system, or process calls, so it is not a malicious install-time or import-time payload.
init() function
NPS-8D4F7E92CB65
The init() function registers register and opcode names for the RISC-V architecture with the Go assembler framework. This is a standard, benign pattern in Go assembler packages and does not perform any file, network, or process operations.
init function
NPS-E152602F2F76
The file contains an init() function that runs at import time, but it only populates an in-memory lookup table (evexSuffixMap) from a static internal table. It performs no network, filesystem, process, or dynamic code execution activity.
Process termination
NPS-4762BF7F1500
versionFlag.Set calls os.Exit(0) during flag parsing. This matches expected Go toolchain behavior for -V flag but represents top-level execution behavior that terminates the process when triggered by specific input.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| goobj/objfile.go | medium | The code is a low-level object file parser with several unsafe memory operations and missing bounds checks, posing a moderate risk if fed untrusted input, but no direct malicious patterns were found. |
| objabi/flag.go | medium | This appears to be a legitimate Go toolchain package (cmd/internal/objabi) with documented response-file expansion and version flag handling; no clear malicious intent, but the arbitrary file read via @files and process exit warrant a warning. |
| asm/arch/arch.go | safe | Cleared by Jev triage; no further analysis needed |
| asm/arch/arm.go | safe | Cleared by Jev triage; no further analysis needed |
| asm/arch/arm64.go | safe | Cleared by Jev triage; no further analysis needed |
| asm/arch/mips.go | safe | Cleared by Jev triage; no further analysis needed |
| asm/arch/ppc64.go | safe | Cleared by Jev triage; no further analysis needed |
| asm/arch/riscv64.go | safe | Cleared by Jev triage; no further analysis needed |
| asm/arch/s390x.go | safe | Cleared by Jev triage; no further analysis needed |
| bio/buf.go | safe | No malicious patterns detected |
| bio/buf_mmap.go | safe | No malicious patterns detected; the code is a standard memory-mapped file reader from the Go standard library's internal bio package with only legitimate OS-level memory mapping. |
| bio/buf_nommap.go | safe | Cleared by Jev triage; no further analysis needed |
| bio/must.go | safe | Cleared by Jev triage; no further analysis needed |
| builder.go | safe | Cleared by Jev triage; no further analysis needed |
| dwarf/dwarf.go | safe | This is the standard Go standard-library dwarf package; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, backdoors, or install-time hooks are present. |
| dwarf/dwarf_defs.go | safe | Cleared by Jev triage; no further analysis needed |
| goobj/builtin.go | safe | No malicious patterns detected |
| goobj/builtinlist.go | safe | No malicious patterns detected; this is a generated Go runtime builtin symbol table with no executable code, network access, or file system manipulation. |
| goobj/funcinfo.go | safe | Cleared by Jev triage; no further analysis needed |
| goobj/mkbuiltin.go | safe | No malicious patterns detected |
| obj/abi_string.go | safe | No malicious patterns detected |
| obj/addrtype_string.go | safe | No malicious patterns detected |
| obj/arm/a.out.go | safe | This file contains only ARM architecture constant definitions and a DWARF register mapping initialization; no malicious patterns were detected. |
| obj/arm/anames.go | safe | No malicious patterns detected |
| obj/arm/anames5.go | safe | Cleared by Jev triage; no further analysis needed |
Show 79 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| obj/arm/asm5.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/arm/list5.go | safe | This is a benign ARM disassembly/formatting helper derived from the Inferno/Plan 9 toolchain with no malicious patterns, network activity, filesystem access, or dynamic code execution. |
| obj/arm/obj5.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/arm64/a.out.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/arm64/anames.go | safe | No malicious patterns detected |
| obj/arm64/anames7.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/arm64/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/arm64/list7.go | safe | No malicious patterns detected; this file is standard Go assembler register and opcode formatting code for the ARM64 architecture. |
| obj/arm64/obj7.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/arm64/sysRegEnc.go | safe | No malicious patterns detected |
| obj/data.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/dwarf.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/go.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/inl.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/ld.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/line.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/link.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/mips/a.out.go | safe | This file contains only MIPS architecture constant definitions and register mappings with no malicious patterns, network activity, or code execution beyond simple initialization checks. |
| obj/mips/anames.go | safe | No malicious patterns detected |
| obj/mips/anames0.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/mips/asm0.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/mips/list0.go | safe | No malicious patterns detected |
| obj/mips/obj0.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/objfile.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/pass.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/pcln.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/plist.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/ppc64/a.out.go | safe | This is a standard Go architecture definitions file for ppc64 with only constants, register mappings, and a benign init() function; no malicious patterns were detected. |
| obj/ppc64/anames.go | safe | No malicious patterns detected; the file is a generated stringer output containing only PowerPC instruction name constants. |
| obj/ppc64/anames9.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/ppc64/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/ppc64/list9.go | safe | No malicious patterns detected; the file contains only register/opcode name formatting for the Go assembler's ppc64 backend. |
| obj/ppc64/obj9.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/riscv/anames.go | safe | No malicious patterns detected |
| obj/riscv/cpu.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/riscv/inst.go | safe | Generated RISC-V instruction encoding table with no executable logic, network calls, or malicious patterns detected. |
| obj/riscv/list.go | safe | No malicious patterns detected; the code is a benign RISC-V register/opcode name registration for the Go assembler, with no network, filesystem, credential, or process activity. |
| obj/riscv/obj.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/s390x/a.out.go | safe | No malicious patterns detected; the file contains only standard Go definitions for s390x architecture constants, register mappings, and DWARF register initialization within an assembler library. |
| obj/s390x/anames.go | safe | No malicious patterns detected |
| obj/s390x/anamesz.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/s390x/condition_code.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/s390x/listz.go | safe | No malicious patterns detected; the file is a standard Go assembler register/opcode name formatter with only init registration and string formatting. |
| obj/s390x/objz.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/s390x/rotate.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/s390x/vector.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/stringer.go | safe | No malicious patterns detected |
| obj/sym.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/textflag.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/util.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/wasm/a.out.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/wasm/anames.go | safe | No malicious patterns detected; this is a generated list of WebAssembly opcode names used by a Go assembler package. |
| obj/wasm/wasmobj.go | safe | This is a legitimate Go WebAssembly assembler backend from the Go standard library (golang-asm) with no malicious patterns detected. |
| obj/x86/a.out.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/x86/aenum.go | safe | No malicious patterns detected |
| obj/x86/anames.go | safe | No malicious patterns detected |
| obj/x86/evex.go | safe | No malicious patterns detected; the init() function only performs benign in-memory initialization of EVEX suffix lookup data with no exfiltration, credential access, dynamic execution, or external I/O. |
| obj/x86/list6.go | safe | No malicious patterns detected |
| obj/x86/obj6.go | safe | Cleared by Jev triage; no further analysis needed |
| obj/x86/ytab.go | safe | Cleared by Jev triage; no further analysis needed |
| objabi/autotype.go | safe | Cleared by Jev triage; no further analysis needed |
| objabi/funcdata.go | safe | Cleared by Jev triage; no further analysis needed |
| objabi/funcid.go | safe | Cleared by Jev triage; no further analysis needed |
| objabi/head.go | safe | Cleared by Jev triage; no further analysis needed |
| objabi/line.go | safe | This is a standard Go standard library utility file for path rewriting and prefix matching with no malicious patterns detected. |
| objabi/path.go | safe | Cleared by Jev triage; no further analysis needed |
| objabi/reloctype.go | safe | Cleared by Jev triage; no further analysis needed |
| objabi/reloctype_string.go | safe | No malicious patterns detected; this is a standard auto-generated stringer file for Go's RelocType enum with no external interactions, dynamic code execution, or suspicious behavior. |
| objabi/stack.go | safe | Cleared by Jev triage; no further analysis needed |
| objabi/symkind.go | safe | Cleared by Jev triage; no further analysis needed |
| objabi/symkind_string.go | safe | No malicious patterns detected |
| objabi/typekind.go | safe | Cleared by Jev triage; no further analysis needed |
| objabi/util.go | safe | No malicious patterns detected; the code is standard Go toolchain configuration logic from the official Go source tree. |
| src/pos.go | safe | Cleared by Jev triage; no further analysis needed |
| src/xpos.go | safe | Cleared by Jev triage; no further analysis needed |
| sys/arch.go | safe | Cleared by Jev triage; no further analysis needed |
| sys/supported.go | safe | Cleared by Jev triage; no further analysis needed |
| unsafeheader/unsafeheader.go | safe | The code is a standard, non-malicious Go package containing type declarations for slice and string headers; it contains no red-flag patterns. |
| unsafeheader/unsafeheader/unsafeheader.go | safe | The code is a standard, non-malicious Go package containing type declarations for slice and string headers; it contains no red-flag patterns. |
Scanned versions of github.com/twitchyliquid64/golang-asm
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| v0.15.1 | Needs review | 104 | Oct 5, 2026 |
Frequently asked questions
Is github.com/twitchyliquid64/golang-asm safe to use?
No confirmed malware was found in github.com/twitchyliquid64/golang-asm@v0.15.1, but the review flagged 3 medium, 8 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/twitchyliquid64/golang-asm contain malware?
No malware was identified in github.com/twitchyliquid64/golang-asm@v0.15.1 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/twitchyliquid64/golang-asm checked?
Togoder Security downloaded the published Go package and had an AI model read its 104 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/twitchyliquid64/golang-asm together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/twitchyliquid64/golang-asm@v0.15.1, cost nothing.