GO-2025-3451
UNKNOWNThis module is a malicious typosquat, attempting to take advantage of confusion with the github.com/boltdb/bolt module.
Confirmed malicious. Do not install it, and remove it where it has been installed.
rat_dropper. Confirmed 2025-03-19, OSV malicious-package feed (Google / OpenSSF).
--- -= Per source details. Do not edit below this line.=- Source: google-open-source-security (9323424d3dfc7569b307842f79fb0c4bd960808214ec219f536fd5bb747422b2) This malicious Go package is a typosquat of the legitimate BoltDB package. It contains a backdoor that enables remote code execution.
Remove it from every machine and lockfile it reached. Treat any credentials, tokens and SSH keys present on those machines as exposed and rotate them. Check CI runners and container images that installed it.
0 direct dependencies
none carry a known advisory
0 packages depend on it
an advisory here reaches each of them
Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.
severity out of 10
chance of exploitation in 30 days
CyberXYZ composite out of 10
fig. 01 — GO-2025-3451, the advisory selected below
This module is a malicious typosquat, attempting to take advantage of confusion with the github.com/boltdb/bolt module.
Checked 2026-10-01 at 00:02 UTC. The most recent advisory here was published 2025-02-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.