The malicious version is still searchable on the Go Module Proxy and has been left undetected for three years, says Boychenko ...