People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!
github.com/shopspring/decimal is a package with over 30K importers. In 2017, a typo-squatted clone named github.com/shopsprint/decimal was added. This is the story of backdoor.TXT record. Based on the records, it would execute a bash command for each record with exec.Command(txt). The malicious code was added via an init() in Golang; this Goroutine is alive for the lifetime of the process but only queries over five minutes.