Hackers Use Single-Letter Go Module Typosquat to Deploy DNS-Based Backdoor
ID: 7ecf2b5c-0db2-52df-a896-18d6211fc1e2
STIX ID: report--7ecf2b5c-0db2-52df-a896-18d6211fc1e2
Feed Name: cybersecurityNews.com
A typosquatted Go module, github.com/shopsprint/decimal (v1.3.3), impersonating the legitimate shopspring/decimal library contains an init() function that opens a DNS TXT‑based command-and-control channel (dnslog-cdn-images.freemyip.com), beacons every five minutes, executes OS commands, and persists due to Go module proxy caching; IoCs including commit and file hashes and the C2 domain are provided and immediate remediation (audit, rotate credentials, monitor DNS) is recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
