Cybersecurity researchers have drawn attention to an attack on the software supply chain that targets the Go ecosystem. The malicious package can grant the adversary remote control of infected systems.
The package, named github.com/boltdb-go/bolt, is a typosquat of the legitimate BoltDB database module (github.com/boltdb/bolt), per Socket. The malicious version (1.3.1) has been published to

