MAL-2025-2546

    Dashboard / Malicious Package / MAL-2025-2546

    MAL-2025-2546

    Published: 19 Mar 2025Last Modified: 19 Mar 2025

    Summary: Malicious code in github.com/ornatedoctrin/layout (Go)

    Details: Source: google-open-source-security (9edf608032bbc84563da5c04376d6add49123c8fdba94883c239857eb45afc40) Malcious typosquatting Go packages targeting Linux and macOS systems used to as a loader to download and run another malicious payload.

    Affected packages

    Package

    Name: github.com/ornatedoctrin/layout

    Purl: pkg:golang/github.com/ornatedoctrin/layout

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    MAL-2025-2546 | CVE-DB