---
id: MAL-2026-17453
title: Malicious code in gocommunity.io/orderedbtree (Go)
summary: Malicious code in gocommunity.io/orderedbtree (Go)
severity: critical
exploited: true
vendor: orderedbtree
product: gocommunity.io/orderedbtree
ecosystem: go
affected:
  - gocommunity.io/orderedbtree
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T07:01:06.319648035Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-17453'
references:
  - url: 'https://www.aikido.dev/blog/graphalgo-terraform-go-modules'
tags:
  - osv
  - go
  - malware
ingestedAt: '2026-10-02T07:24:14.791Z'
---

## Overview

Part of the Graphalgo campaign. The module, first published around 2026-08-11, contains a second-stage remote access trojan in plaintext that runs automatically. The RAT collects system information, executes decrypted Go or JavaScript payloads, and polls two command-and-control channels every 3-10 seconds: an Ethereum smart contract used as a dead drop (Arbitrum Sepolia) and a Slack bot token.

## Affected packages

- `gocommunity.io/orderedbtree`

## Remediation

Refer to the advisory for the patched release.
