MAL-2025-49377
Dashboard / Malicious Package / MAL-2025-49377
MAL-2025-49377
Published: 24 Oct 2025Last Modified: 4 Feb 2026
Summary: Malicious code in github.com/boltdb-go/bolt (Git)
Details: Source: google-open-source-security (1cad7a46a80076eedc2c3c00be0d3215bdfed842f6cc04c238d3b2591b38e2ad) This malicious git repository is a typosquat of the legitimate BoltDB Go package. It contains a backdoor that enables remote code execution.
References: https://socket.dev/blog/malicious-package-exploits-go-module-proxy-caching-for-persistence
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 0
Fixed -None
