{"id":"MAL-2025-49377","summary":"Malicious code in github.com/boltdb-go/bolt (Git)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: google-open-source-security (1cad7a46a80076eedc2c3c00be0d3215bdfed842f6cc04c238d3b2591b38e2ad)\nThis malicious git repository is a typosquat of the legitimate BoltDB Go package.\nIt contains a backdoor that enables remote code execution.\n","modified":"2026-02-04T02:34:58.026628Z","published":"2025-10-24T02:43:05Z","related":["GO-2025-3451","MAL-2025-2545"],"database_specific":{"malicious-packages-origins":[{"modified_time":"2025-10-24T02:43:05Z","ranges":[{"events":[{"introduced":"0"}],"repo":"git@github.com:boltdb-go/bolt.git","type":"GIT"}],"sha256":"1cad7a46a80076eedc2c3c00be0d3215bdfed842f6cc04c238d3b2591b38e2ad","source":"google-open-source-security","import_time":"2025-11-05T23:55:12.167979Z"}]},"references":[{"type":"ARTICLE","url":"https://socket.dev/blog/malicious-package-exploits-go-module-proxy-caching-for-persistence"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/boltdb-go/bolt.git","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/git/github.com/boltdb-go/bolt/MAL-2025-49377.json"}}],"schema_version":"1.7.3","credits":[{"name":"Socket","type":"FINDER"}]}