Poisoned Code: Stealthy Malicious Go Module Backdoor Discovered in Long-Running Typosquat
ID: 617b0476-600d-5c17-b4ec-031df77d51f1
STIX ID: report--617b0476-600d-5c17-b4ec-031df77d51f1
Feed Name: securityonline.info
Socket’s Threat Research Team discovered a typosquatted Go module (`github.com/shopsprint/decimal`) that impersonated the popular `github.com/shopspring/decimal` library. The attacker published benign updates for years, then weaponized the module (v1.3.3, 2023-08-19) to run a stealthy DNS TXT-based backdoor: an init() goroutine polls a hardcoded subdomain every five minutes and executes returned TXT record strings via exec.Command, enabling arbitrary remote code execution on any system that imports the package and posing high risk to developer machines, CI/CD pipelines, and production infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
