-= Per source details. Do not edit below this line.=-
This malicious git repository is a typosquat of the legitimate BoltDB Go package. It contains a backdoor that enables remote code execution.
{
"malicious-packages-origins": [
{
"sha256": "1cad7a46a80076eedc2c3c00be0d3215bdfed842f6cc04c238d3b2591b38e2ad",
"import_time": "2025-11-05T23:55:12.167979Z",
"ranges": [
{
"repo": "git@github.com:boltdb-go/bolt.git",
"type": "GIT",
"events": [
{
"introduced": "0"
}
]
}
],
"modified_time": "2025-10-24T02:43:05Z",
"source": "google-open-source-security"
}
]
}