SentinelOne describes this as a malware written in Go, mixing own custom code with code from public repositories.