Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Do not pass GO - Malicious Package Alert

Blog post from Snyk

Post Details
Company
Date Published
Author
Vandana Verma Sehgal
Word Count
477
Company Posts That Month
9
Language
English
Hacker News Points
-
Post removed?
No
Summary

The BoltDB Go Module was found to be backdoored with malicious code that allowed hackers to remotely control infected computers through a command and control server. The malicious package, which was released in November 2021, was cached by the Go Module Mirror service and remained unnoticed for several years. Researchers discovered the issue on January 30, 2025, and it had affected thousands of organizations over three years. The incident highlights a significant flaw in the software supply chain ecosystem, with malicious packages still being searchable on Go Module Proxy. To mitigate such risks, it is essential to follow best practices and use tools like Snyk to secure the software supply chain.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.