{"id":"MAL-2026-17453","title":"Malicious code in gocommunity.io/orderedbtree (Go)","summary":"Malicious code in gocommunity.io/orderedbtree (Go)","severity":"critical","exploited":true,"vendor":"orderedbtree","product":"gocommunity.io/orderedbtree","ecosystem":"go","affected":["gocommunity.io/orderedbtree"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T07:01:06.319648035Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-17453","references":[{"url":"https://www.aikido.dev/blog/graphalgo-terraform-go-modules"}],"tags":["osv","go","malware"],"ingestedAt":"2026-10-02T07:24:14.791Z","slug":"MAL-2026-17453","body":"## Overview\n\nPart of the Graphalgo campaign. The module, first published around 2026-08-11, contains a second-stage remote access trojan in plaintext that runs automatically. The RAT collects system information, executes decrypted Go or JavaScript payloads, and polls two command-and-control channels every 3-10 seconds: an Ethereum smart contract used as a dead drop (Arbitrum Sepolia) and a Slack bot token.\n\n## Affected packages\n\n- `gocommunity.io/orderedbtree`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}