MAL-2025-2551

    Dashboard / Malicious Package / MAL-2025-2551

    MAL-2025-2551

    Published: 19 Mar 2025Last Modified: 19 Mar 2025

    Summary: Malicious code in github.com/vainreboot/layout (Go)

    Details: Source: google-open-source-security (cd535431a1bde903495e71799081c385016d84659ac004c1c57c0d81e311ee59) Malcious typosquatting Go packages targeting Linux and macOS systems used to as a loader to download and run another malicious payload.

    Affected packages

    Package

    Name: github.com/vainreboot/layout

    Purl: pkg:golang/github.com/vainreboot/layout

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    MAL-2025-2551 | CVE-DB