-= Per source details. Do not edit below this line.=-
This malicious Go package is a typosquat of the legitimate BoltDB package. It contains a backdoor that enables remote code execution.
{
"malicious-packages-origins": [
{
"import_time": "2025-03-20T00:02:04.789836Z",
"modified_time": "2025-03-19T23:54:27Z",
"source": "google-open-source-security",
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
],
"sha256": "9323424d3dfc7569b307842f79fb0c4bd960808214ec219f536fd5bb747422b2"
}
]
}