Single-Letter Go Module Typosquat Spreads DNS-Based Backdoor
ID: 10dae8ff-0b1c-5a31-9711-1aaec30ff9a5
STIX ID: report--10dae8ff-0b1c-5a31-9711-1aaec30ff9a5
Feed Name: Cyber Press
**Executive summary:** A malicious Go typosquat package (github.com/shopsprint/decimal) — a one-character impersonation of shopspring/decimal — contained a hidden init() function introduced in v1.3.3 that polls a freemyip.com subdomain for DNS TXT records every five minutes and passes returned text to the system command executor, enabling arbitrary remote command execution; the poisoned module persisted in the Go Module Proxy cache for years and can compromise developer workstations, CI/CD runners, and production systems. IOCs listed include the package name, version v1.3.3, C2 domain dnslog-cdn-images.freemyip.com, and a decoy A record of 8.8.8.8; recommended mitigations include auditing go.mod/go.sum, replacing the dependency, blocking DNS to freemyip.com, and scanning caches/binaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
