logo

Poisoned Go programming language package lay undetected for 3 years

ID: 3e8841dd-7d87-56a6-9f51-d2e6ca467cad

STIX ID: report--3e8841dd-7d87-56a6-9f51-d2e6ca467cad

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2025-02-04

Date Updated: 2026-04-26

Author: Connor Jones

...
...

A typosquatted Go module (github.com/boltdb-go/bolt) contained a backdoor that enabled remote code execution and was cached by the Go Module Mirror for about three years, allowing persistent distribution to developers who accidentally imported the malicious package instead of the legitimate boltdb. The attacker used tag manipulation so manual reviews pointed to the real project while the malicious version remained served; Socket Security reported the package and Google removed it and added it to the Go vulnerability database.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.