ThreatCluster

Single-Letter Go Module Typosquat Introduces Persistent Backdoor

First seen 20 May 2026, 13:07 UTC GbhackersCybersecuritynews 93% similarity 68

Article Content

Browse articles
ThreatCluster

A malicious Go module named github.com/shopsprint/decimal has been discovered, impersonating the legitimate github.com/shopspring/decimal library. This typosquatting attack has been active since 2017 and was weaponized in August 2023, allowing attackers to deploy a persistent backdoor. The legitimate package is widely used, with over 38,000 known downloads, affecting numerous Go developers and applications reliant on high-precision arithmetic. Security researchers have confirmed the ongoing risk posed by this malicious package, which could compromise sensitive data and systems. Developers are urged to verify their dependencies to prevent exploitation. The current status of the threat remains active, with no immediate resolution reported.

Key Points: • A malicious Go module has impersonated a widely used library since 2017. • The attack was weaponized in August 2023, introducing a persistent backdoor. • Developers are advised to check their dependencies to mitigate risks.

ThreatCluster AI

Timeline

2017-01-01
Malicious Go module created
The typosquatting module github.com/shopsprint/decimal was made available, mimicking a legitimate library.
Gbhackers
2023-08-01
Module weaponized
Attackers modified the malicious module to deploy a persistent backdoor, increasing its threat level.
Cybersecuritynews
2026-05-20
Discovery of the attack
Security researchers uncovered the ongoing risk posed by the typosquatting module, prompting alerts to developers.
Gbhackers

Community

Browse all →

Tracked Entities in This Story