{"id":"MAL-2026-17453","summary":"Malicious code in gocommunity.io/orderedbtree (Go)","details":"Part of the Graphalgo campaign. The module, first published around 2026-08-11, contains a second-stage remote access trojan in plaintext that runs automatically. The RAT collects system information, executes decrypted Go or JavaScript payloads, and polls two command-and-control channels every 3-10 seconds: an Ethereum smart contract used as a dead drop (Arbitrum Sepolia) and a Slack bot token.","modified":"2026-10-02T07:01:06.319648035Z","published":"2026-10-02T00:00:00Z","database_specific":{"iocs":{"domains":["gocommunity.io","gogets.dev","portfolio-devs.slack.com","portfolio-testers.slack.com","mediumstar.slack.com"],"files":[{"digests":{"sha256":"5f892a5424e88a21a3eb3d7f82ebf04d8ac31cdb19ada25153be4165df977d0f"},"paths":["import-resource.sqlite3"]}]}},"references":[{"type":"ARTICLE","url":"https://www.aikido.dev/blog/graphalgo-terraform-go-modules"}],"affected":[{"package":{"name":"gocommunity.io/orderedbtree","ecosystem":"Go","purl":"pkg:golang/gocommunity.io/orderedbtree"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/go/gocommunity.io/orderedbtree/MAL-2026-17453.json"}}],"schema_version":"1.9.0","credits":[{"name":"Aikido Security","type":"FINDER"}]}