logo

Poisoned Code: Stealthy Malicious Go Module Backdoor Discovered in Long-Running Typosquat

ID: 617b0476-600d-5c17-b4ec-031df77d51f1

STIX ID: report--617b0476-600d-5c17-b4ec-031df77d51f1

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: Ddos

...
...

Socket’s Threat Research Team discovered a typosquatted Go module (`github.com/shopsprint/decimal`) that impersonated the popular `github.com/shopspring/decimal` library. The attacker published benign updates for years, then weaponized the module (v1.3.3, 2023-08-19) to run a stealthy DNS TXT-based backdoor: an init() goroutine polls a hardcoded subdomain every five minutes and executes returned TXT record strings via exec.Command, enabling arbitrary remote code execution on any system that imports the package and posing high risk to developer machines, CI/CD pipelines, and production infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.