MAL-2026-17453

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/go/gocommunity.io/orderedbtree/MAL-2026-17453.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17453
Published
2026-10-02T00:00:00Z
Modified
2026-10-02T07:01:06Z
Summary
Malicious code in gocommunity.io/orderedbtree (Go)
Details

Part of the Graphalgo campaign. The module, first published around 2026-08-11, contains a second-stage remote access trojan in plaintext that runs automatically. The RAT collects system information, executes decrypted Go or JavaScript payloads, and polls two command-and-control channels every 3-10 seconds: an Ethereum smart contract used as a dead drop (Arbitrum Sepolia) and a Slack bot token.

Database specific
{
    "iocs":  {
        "domains":  [
            "gocommunity.io",
            "gogets.dev",
            "portfolio-devs.slack.com",
            "portfolio-testers.slack.com",
            "mediumstar.slack.com"
        ],
        "files":  [
            {
                "digests":  {
                    "sha256":  "5f892a5424e88a21a3eb3d7f82ebf04d8ac31cdb19ada25153be4165df977d0f"
                },
                "paths":  [
                    "import-resource.sqlite3"
                ]
            }
        ]
    }
}
References
Credits
    • Aikido Security - FINDER

Affected packages

Go / gocommunity.io/orderedbtree

Package

Name
gocommunity.io/orderedbtree
View open source insights on deps.dev
Purl
pkg:golang/gocommunity.io/orderedbtree

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/go/gocommunity.io/orderedbtree/MAL-2026-17453.json"