# Do not pass GO - Malicious Package Alert

DevFeed: [Do not pass GO - Malicious Package Alert](<https://devfeed.tech/articles/do-not-pass-go-malicious-package-alert-7943.md>)

Original publisher: [Read original article](<https://snyk.io/blog/go-malicious-package-alert/>)

Author: Vandana Verma Sehgal

Published: 2025-02-12T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Go Language](<https://devfeed.tech/topics/go-language.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [database](<https://devfeed.tech/tags/database.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [go](<https://devfeed.tech/tags/go.md>), [interest](<https://devfeed.tech/tags/interest.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

The article reports that a typosquatted BoltDB Go module contained a backdoor and remained available through Go module caching. It describes the reported impact and the removal of the module from GitHub and the Go module proxy.

## Source excerpt

Recently, researchers have found another Software Supply Chain issue in BoltDB, a popular database tool in the Go programming environment. The BoltDB Go Module was found backdoored and contained hidden malicious code.