<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[(socket.dev) Typosquatted Go Module Weaponized with DNS-Based Command and Control: Analysis of github.com&#x2F;shopsprint&#x2F;decimal]]></title><description><![CDATA[<p>(socket.dev) Typosquatted Go Module Weaponized with DNS-Based Command and Control: Analysis of github.com/shopsprint/decimal</p><p>New supply chain threat: Typosquatted Go module github.com/shopsprint/decimal (v1.3.3) backdoors systems via DNS TXT-based C2. Module remains accessible via Go proxy despite repo takedown.</p><p>In brief - A malicious Go module impersonating the popular shopspring/decimal library was weaponized in August 2023 with a DNS-based backdoor. The attack abuses Go's init() function to execute arbitrary commands from TXT records, posing a persistent risk to developers.</p><p>Technically - The typosquatted github.com/shopsprint/decimal (v1.3.3) abuses Go's init() function to poll dnslog-cdn-images.freemyip.com every 5 minutes for TXT records, executing returned commands via os/exec.Command. The C2 leverages dynamic DNS and evades detection by preserving the legitimate API. Detection requires auditing go.mod for the typosquatted import and scanning for anomalous imports (net, os/exec, time) in non-network libraries.</p><p>Source: <a href="https://socket.dev/blog/popular-go-decimal-library-typosquat-dns-backdoor" rel="nofollow noopener"><span>https://</span><span>socket.dev/blog/popular-go-dec</span><span>imal-library-typosquat-dns-backdoor</span></a></p><p><a href="https://swecyb.com/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/ThreatIntel" rel="tag">#<span>ThreatIntel</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/3720e7de-e500-4270-aeed-e21750b89027/socket.dev-typosquatted-go-module-weaponized-with-dns-based-command-and-control-analysis-of-github.com-shopsprint-decimal</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 11:24:28 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/3720e7de-e500-4270-aeed-e21750b89027.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 19 May 2026 17:58:55 GMT</pubDate><ttl>60</ttl></channel></rss>