Togoder security

Go package security report

github.com/twitchyliquid64/golang-asm@v0.15.1 security report

Risky patterns found that deserve a look.

Needs review Version v0.15.1 Files reviewed 104 Size 1.8 MB Scanned

Summary

Togoder Security scanned the Go package github.com/twitchyliquid64/golang-asm@v0.15.1 on Oct 5, 2026. An AI review of 104 source files produced 3 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
8
low

Findings 11

medium

Lack of input validation on object file data

NPS-5526BF3FB335

The Reader methods compute offsets and lengths based on the header's Offsets array without validating that they are within the bounds of the provided byte slice. A malicious object file could cause panics (index out of range) or out-of-bounds reads, potentially leading to denial of service or memory corruption.

goobj/objfile.go:476
medium

Potential out-of-bounds read

NPS-9B239EF72029

Several methods use unsafe.Pointer to cast byte slices to structs (e.g., Sym, Reloc, Aux). There is no bounds checking in these casts, which could lead to out-of-bounds reads if the object file is malformed. This is a common pattern in low-level parsers but can be exploited to cause crashes or information disclosure.

goobj/objfile.go:636
medium

File system manipulation / Response file expansion

NPS-F17D43E2A11C

The expandArgs function reads arbitrary files specified by '@filename' command-line arguments using ioutil.ReadFile(s[1:]). This enables an attacker who can influence command-line arguments to cause the tool to read any file readable by the process. While not inherently malicious and matching documented Go toolchain behavior, it is an unusual file-read capability that could be abused for data exfiltration if combined with other flaws.

objabi/flag.go:45
low

external process execution

NPS-73ED6E49D2BB

The function IsDWARFEnabledOnAIXLd executes an external linker binary (extld) with the -Wl,-V flag to check its version on AIX. This is a legitimate, narrowly scoped use for DWARF configuration on AIX and does not perform arbitrary command execution or shell injection. No user-controlled input is interpolated into a shell, and no suspicious behavior is present.

dwarf/dwarf.go:732
low

Unsafe string construction from read-only memory

NPS-025661200781

The toString function uses unsafe.Pointer to convert a byte slice backed by read-only memory into a string without copying. If the underlying memory is later modified (e.g., via unsafe pointers elsewhere), it could lead to data corruption or security issues. However, the code checks r.readonly before calling it, so the risk is mitigated.

goobj/objfile.go:594
low

Use of `unsafe` package for performance

NPS-FA52C120820A

The code extensively uses unsafe to reinterpret byte slices as structs and to create strings without copying. While this is typical for performance-critical parsers, it increases the risk of memory safety issues if not carefully audited.

goobj/objfile.go:594
low

init-time registration

NPS-A9197299A78F

The init() function registers ARM register/opcode formatting handlers with the Go object package. This is normal for Go toolchain libraries and only mutates in-process tables; it performs no network, filesystem, or process operations.

obj/arm/list5.go:33
low

Go init function

NPS-7C1016961F9C

The file contains an init() function that populates a DWARF register mapping table. It only performs local map assignments and makes no network, file system, or process calls, so it is not a malicious install-time or import-time payload.

obj/ppc64/a.out.go:213
low

init() function

NPS-8D4F7E92CB65

The init() function registers register and opcode names for the RISC-V architecture with the Go assembler framework. This is a standard, benign pattern in Go assembler packages and does not perform any file, network, or process operations.

obj/riscv/list.go:11
low

init function

NPS-E152602F2F76

The file contains an init() function that runs at import time, but it only populates an in-memory lookup table (evexSuffixMap) from a static internal table. It performs no network, filesystem, process, or dynamic code execution activity.

obj/x86/evex.go:155
low

Process termination

NPS-4762BF7F1500

versionFlag.Set calls os.Exit(0) during flag parsing. This matches expected Go toolchain behavior for -V flag but represents top-level execution behavior that terminates the process when triggered by specific input.

objabi/flag.go:97

Files reviewed

FileVerdictWhat the reviewer saw
goobj/objfile.go medium The code is a low-level object file parser with several unsafe memory operations and missing bounds checks, posing a moderate risk if fed untrusted input, but no direct malicious patterns were found.
objabi/flag.go medium This appears to be a legitimate Go toolchain package (cmd/internal/objabi) with documented response-file expansion and version flag handling; no clear malicious intent, but the arbitrary file read via @files and process exit warrant a warning.
asm/arch/arch.go safe Cleared by Jev triage; no further analysis needed
asm/arch/arm.go safe Cleared by Jev triage; no further analysis needed
asm/arch/arm64.go safe Cleared by Jev triage; no further analysis needed
asm/arch/mips.go safe Cleared by Jev triage; no further analysis needed
asm/arch/ppc64.go safe Cleared by Jev triage; no further analysis needed
asm/arch/riscv64.go safe Cleared by Jev triage; no further analysis needed
asm/arch/s390x.go safe Cleared by Jev triage; no further analysis needed
bio/buf.go safe No malicious patterns detected
bio/buf_mmap.go safe No malicious patterns detected; the code is a standard memory-mapped file reader from the Go standard library's internal bio package with only legitimate OS-level memory mapping.
bio/buf_nommap.go safe Cleared by Jev triage; no further analysis needed
bio/must.go safe Cleared by Jev triage; no further analysis needed
builder.go safe Cleared by Jev triage; no further analysis needed
dwarf/dwarf.go safe This is the standard Go standard-library dwarf package; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, backdoors, or install-time hooks are present.
dwarf/dwarf_defs.go safe Cleared by Jev triage; no further analysis needed
goobj/builtin.go safe No malicious patterns detected
goobj/builtinlist.go safe No malicious patterns detected; this is a generated Go runtime builtin symbol table with no executable code, network access, or file system manipulation.
goobj/funcinfo.go safe Cleared by Jev triage; no further analysis needed
goobj/mkbuiltin.go safe No malicious patterns detected
obj/abi_string.go safe No malicious patterns detected
obj/addrtype_string.go safe No malicious patterns detected
obj/arm/a.out.go safe This file contains only ARM architecture constant definitions and a DWARF register mapping initialization; no malicious patterns were detected.
obj/arm/anames.go safe No malicious patterns detected
obj/arm/anames5.go safe Cleared by Jev triage; no further analysis needed
Show 79 more files
FileVerdictWhat the reviewer saw
obj/arm/asm5.go safe Cleared by Jev triage; no further analysis needed
obj/arm/list5.go safe This is a benign ARM disassembly/formatting helper derived from the Inferno/Plan 9 toolchain with no malicious patterns, network activity, filesystem access, or dynamic code execution.
obj/arm/obj5.go safe Cleared by Jev triage; no further analysis needed
obj/arm64/a.out.go safe Cleared by Jev triage; no further analysis needed
obj/arm64/anames.go safe No malicious patterns detected
obj/arm64/anames7.go safe Cleared by Jev triage; no further analysis needed
obj/arm64/doc.go safe Cleared by Jev triage; no further analysis needed
obj/arm64/list7.go safe No malicious patterns detected; this file is standard Go assembler register and opcode formatting code for the ARM64 architecture.
obj/arm64/obj7.go safe Cleared by Jev triage; no further analysis needed
obj/arm64/sysRegEnc.go safe No malicious patterns detected
obj/data.go safe Cleared by Jev triage; no further analysis needed
obj/dwarf.go safe Cleared by Jev triage; no further analysis needed
obj/go.go safe Cleared by Jev triage; no further analysis needed
obj/inl.go safe Cleared by Jev triage; no further analysis needed
obj/ld.go safe Cleared by Jev triage; no further analysis needed
obj/line.go safe Cleared by Jev triage; no further analysis needed
obj/link.go safe Cleared by Jev triage; no further analysis needed
obj/mips/a.out.go safe This file contains only MIPS architecture constant definitions and register mappings with no malicious patterns, network activity, or code execution beyond simple initialization checks.
obj/mips/anames.go safe No malicious patterns detected
obj/mips/anames0.go safe Cleared by Jev triage; no further analysis needed
obj/mips/asm0.go safe Cleared by Jev triage; no further analysis needed
obj/mips/list0.go safe No malicious patterns detected
obj/mips/obj0.go safe Cleared by Jev triage; no further analysis needed
obj/objfile.go safe Cleared by Jev triage; no further analysis needed
obj/pass.go safe Cleared by Jev triage; no further analysis needed
obj/pcln.go safe Cleared by Jev triage; no further analysis needed
obj/plist.go safe Cleared by Jev triage; no further analysis needed
obj/ppc64/a.out.go safe This is a standard Go architecture definitions file for ppc64 with only constants, register mappings, and a benign init() function; no malicious patterns were detected.
obj/ppc64/anames.go safe No malicious patterns detected; the file is a generated stringer output containing only PowerPC instruction name constants.
obj/ppc64/anames9.go safe Cleared by Jev triage; no further analysis needed
obj/ppc64/doc.go safe Cleared by Jev triage; no further analysis needed
obj/ppc64/list9.go safe No malicious patterns detected; the file contains only register/opcode name formatting for the Go assembler's ppc64 backend.
obj/ppc64/obj9.go safe Cleared by Jev triage; no further analysis needed
obj/riscv/anames.go safe No malicious patterns detected
obj/riscv/cpu.go safe Cleared by Jev triage; no further analysis needed
obj/riscv/inst.go safe Generated RISC-V instruction encoding table with no executable logic, network calls, or malicious patterns detected.
obj/riscv/list.go safe No malicious patterns detected; the code is a benign RISC-V register/opcode name registration for the Go assembler, with no network, filesystem, credential, or process activity.
obj/riscv/obj.go safe Cleared by Jev triage; no further analysis needed
obj/s390x/a.out.go safe No malicious patterns detected; the file contains only standard Go definitions for s390x architecture constants, register mappings, and DWARF register initialization within an assembler library.
obj/s390x/anames.go safe No malicious patterns detected
obj/s390x/anamesz.go safe Cleared by Jev triage; no further analysis needed
obj/s390x/condition_code.go safe Cleared by Jev triage; no further analysis needed
obj/s390x/listz.go safe No malicious patterns detected; the file is a standard Go assembler register/opcode name formatter with only init registration and string formatting.
obj/s390x/objz.go safe Cleared by Jev triage; no further analysis needed
obj/s390x/rotate.go safe Cleared by Jev triage; no further analysis needed
obj/s390x/vector.go safe Cleared by Jev triage; no further analysis needed
obj/stringer.go safe No malicious patterns detected
obj/sym.go safe Cleared by Jev triage; no further analysis needed
obj/textflag.go safe Cleared by Jev triage; no further analysis needed
obj/util.go safe Cleared by Jev triage; no further analysis needed
obj/wasm/a.out.go safe Cleared by Jev triage; no further analysis needed
obj/wasm/anames.go safe No malicious patterns detected; this is a generated list of WebAssembly opcode names used by a Go assembler package.
obj/wasm/wasmobj.go safe This is a legitimate Go WebAssembly assembler backend from the Go standard library (golang-asm) with no malicious patterns detected.
obj/x86/a.out.go safe Cleared by Jev triage; no further analysis needed
obj/x86/aenum.go safe No malicious patterns detected
obj/x86/anames.go safe No malicious patterns detected
obj/x86/evex.go safe No malicious patterns detected; the init() function only performs benign in-memory initialization of EVEX suffix lookup data with no exfiltration, credential access, dynamic execution, or external I/O.
obj/x86/list6.go safe No malicious patterns detected
obj/x86/obj6.go safe Cleared by Jev triage; no further analysis needed
obj/x86/ytab.go safe Cleared by Jev triage; no further analysis needed
objabi/autotype.go safe Cleared by Jev triage; no further analysis needed
objabi/funcdata.go safe Cleared by Jev triage; no further analysis needed
objabi/funcid.go safe Cleared by Jev triage; no further analysis needed
objabi/head.go safe Cleared by Jev triage; no further analysis needed
objabi/line.go safe This is a standard Go standard library utility file for path rewriting and prefix matching with no malicious patterns detected.
objabi/path.go safe Cleared by Jev triage; no further analysis needed
objabi/reloctype.go safe Cleared by Jev triage; no further analysis needed
objabi/reloctype_string.go safe No malicious patterns detected; this is a standard auto-generated stringer file for Go's RelocType enum with no external interactions, dynamic code execution, or suspicious behavior.
objabi/stack.go safe Cleared by Jev triage; no further analysis needed
objabi/symkind.go safe Cleared by Jev triage; no further analysis needed
objabi/symkind_string.go safe No malicious patterns detected
objabi/typekind.go safe Cleared by Jev triage; no further analysis needed
objabi/util.go safe No malicious patterns detected; the code is standard Go toolchain configuration logic from the official Go source tree.
src/pos.go safe Cleared by Jev triage; no further analysis needed
src/xpos.go safe Cleared by Jev triage; no further analysis needed
sys/arch.go safe Cleared by Jev triage; no further analysis needed
sys/supported.go safe Cleared by Jev triage; no further analysis needed
unsafeheader/unsafeheader.go safe The code is a standard, non-malicious Go package containing type declarations for slice and string headers; it contains no red-flag patterns.
unsafeheader/unsafeheader/unsafeheader.go safe The code is a standard, non-malicious Go package containing type declarations for slice and string headers; it contains no red-flag patterns.

Frequently asked questions

Is github.com/twitchyliquid64/golang-asm safe to use?

No confirmed malware was found in github.com/twitchyliquid64/golang-asm@v0.15.1, but the review flagged 3 medium, 8 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/twitchyliquid64/golang-asm contain malware?

No malware was identified in github.com/twitchyliquid64/golang-asm@v0.15.1 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/twitchyliquid64/golang-asm checked?

Togoder Security downloaded the published Go package and had an AI model read its 104 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/twitchyliquid64/golang-asm together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/twitchyliquid64/golang-asm@v0.15.1, cost nothing.

Related security reports