{"id":"MAL-2026-17454","title":"Malicious code in gogets.dev/btreex (Go)","summary":"Malicious code in gogets.dev/btreex (Go)","severity":"critical","exploited":true,"vendor":"btreex","product":"gogets.dev/btreex","ecosystem":"go","affected":["gogets.dev/btreex"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T07:01:06.603753419Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-17454","references":[{"url":"https://www.aikido.dev/blog/graphalgo-terraform-go-modules"}],"tags":["osv","go","malware"],"ingestedAt":"2026-10-02T07:24:14.791Z","slug":"MAL-2026-17454","body":"## Overview\n\nPart of the Graphalgo campaign. The module, first published around 2026-09-08, hides its payload in a ZIP archive disguised as a SQL file (btreex.sql). The payload is triggered when a specific price integer value is passed, and drops the same dual-channel RAT (Ethereum smart contract dead drop plus Slack bot token) used by gocommunity.io/orderedbtree.\n\n## Affected packages\n\n- `gogets.dev/btreex`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}