Corpus graph previewActor to Incident
Supply Chain GraphPan, zoom, and select actor, campaign, and incident tiers.

Supply Chain graph is loading. Keyboard controls become available after graph initialization.

Supply Chain Incident

Focused Graph View

The persistent graph is framed to this incident while the canonical page heading and details continue below.

270 nodes467 edgesCold links hydrate here

Supply Chain Incident

Go BoltDB typosquat module proxy backdoor

Socket researchers disclosed a backdoored Go module typosquatting BoltDB that persisted through Go Module Proxy caching even after the source repository tag was changed.

ConfidenceHigh
Evidence LevelResearcher
Attack StageDependency Resolution
Source Artifact DivergenceYes
Attribution ConfidenceSuspected

Affected Packages

Affected Releases

  • github.com/boltdb-go/bolt@v1.3.1pkg:golang/github.com/boltdb-go/bolt@v1.3.1 · published 2021-11-01Release

Repositories

Organizations

No structured records.

Maintainers

No structured records.

Threat Actors

  • boltdb-go operator

Campaigns

No structured records.

Build Systems

No structured records.

Distribution Channels

  • GitHub repository
  • Go Module Proxy

Compromised Accounts

No structured records.

Connected Entities

  • boltdb-go operatorThreat Actor
  • boltdb-go/boltRepository
  • GitHub repositoryDistribution Channel
  • github.com/boltdb-go/boltPackage
  • github.com/boltdb-go/bolt@v1.3.1Release
  • Go Module ProxyDistribution Channel

Attribution Evidence

References