A typosquat of boltdb/bolt containing an RCE backdoor. First documented exploit of Go Module Mirror's indefinite caching — after the module was cached, the attacker modified Git tags to point to benign code, but the Mirror continued serving the malicious cached version. Persisted undetected for 3+ years.
PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package |
| Socket | Caught | Typosquatting detection across ecosystems |
| Snyk | Missed | No typosquatting detection |
| Sonatype (Nexus) | Missed | Weaker ecosystem coverage |
| Black Duck | Missed | No typosquatting detection |
| Endor Labs | Missed | No typosquatting detection |