MAL-2026-17454

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/go/gogets.dev/btreex/MAL-2026-17454.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17454
Published
2026-10-02T00:00:00Z
Modified
2026-10-02T07:01:06Z
Summary
Malicious code in gogets.dev/btreex (Go)
Details

Part of the Graphalgo campaign. The module, first published around 2026-09-08, hides its payload in a ZIP archive disguised as a SQL file (btreex.sql). The payload is triggered when a specific price integer value is passed, and drops the same dual-channel RAT (Ethereum smart contract dead drop plus Slack bot token) used by gocommunity.io/orderedbtree.

Database specific
{
    "iocs":  {
        "domains":  [
            "gocommunity.io",
            "gogets.dev",
            "portfolio-devs.slack.com",
            "portfolio-testers.slack.com",
            "mediumstar.slack.com"
        ],
        "files":  [
            {
                "digests":  {
                    "sha256":  "ab01686d87565250fc4989faddb877d793667b07ec217a61cbd798f5695d62f5"
                },
                "paths":  [
                    "btreex.sql"
                ]
            }
        ]
    }
}
References
Credits
    • Aikido Security - FINDER

Affected packages

Go / gogets.dev/btreex

Package

Name
gogets.dev/btreex
View open source insights on deps.dev
Purl
pkg:golang/gogets.dev/btreex

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/go/gogets.dev/btreex/MAL-2026-17454.json"