Summary
Togoder Security scanned the Go package github.com/klauspost/cpuid/v2@v2.2.9 on Oct 5, 2026. An AI review of 11 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
import-time execution
NPS-6C3311CD968E
The package runs init() at import time which calls initCPU() and Detect(). Detect() parses command-line flags (cpu.disable, cpu.features, cpu.arm) and may call os.Exit(1) if -cpu.features is set. This is a behavior that modifies process behavior and can terminate the host program unexpectedly based solely on ambient flag values, which is unusual for a library.
process termination from library code
NPS-CA02678BEF26
The Detect() function calls os.Exit(1) when the -cpu.features flag is enabled. Library code should not terminate the calling process; this can be abused or cause unexpected denial of service when flags are supplied by a parent process.
global flag registration side effect
NPS-C296ED3693AA
Flags() registers global command-line flags (cpu.disable, cpu.features, cpu.arm) which, if called before flag.Parse, influences parsing of the host application's command line. This is a side effect not typical for a CPU detection library and could interfere with the host program.
use of go:linkname
NPS-4F4592837213
This file uses //go:linkname to access the unexported symbol internal/cpu.HWCap from the Go standard library. While not inherently malicious, go:linkname is a powerful unsafe mechanism that bypasses Go's type safety and module boundaries. It relies on undocumented internal implementation details, may break across Go versions, and can be abused to access or alter internal runtime/stdlib state. It is gated behind a build tag (!nounsafe), which is a reasonable mitigation. No data exfiltration, credential harvesting, process spawning, or dynamic code execution is present.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| cpuid.go | medium | The cpuid library contains import-time CPU detection and command-line flag/exit side effects, but no data exfiltration, credential harvesting, obfuscation, network activity, or process spawning was observed. |
| os_unsafe_linux_arm64.go | medium | The file is not malicious but uses the unsafe go:linkname directive to access an internal standard library symbol, which warrants caution due to its fragility and potential for abuse. |
| cmd/cpuid/main.go | safe | No malicious patterns detected |
| detect_arm64.go | safe | No malicious patterns detected |
| detect_ref.go | safe | No malicious patterns detected; the file contains only stub implementations for CPU feature detection on unsupported architectures. |
| detect_x86.go | safe | No malicious patterns detected; the file contains only CPU feature detection declarations and initialization for x86 architectures. |
| featureid_string.go | safe | No malicious patterns detected |
| os_darwin_arm64.go | safe | No malicious patterns detected; the code only reads macOS sysctl values to populate CPU feature information. |
| os_linux_arm64.go | safe | No malicious patterns detected |
| os_other_arm64.go | safe | No malicious patterns detected; the file only reads CPU core counts via runtime.NumCPU for ARM64 non-Linux/non-Darwin platforms. |
| os_safe_linux_arm64.go | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is github.com/klauspost/cpuid/v2 safe to use?
No confirmed malware was found in github.com/klauspost/cpuid/v2@v2.2.9, but the review flagged 2 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/klauspost/cpuid/v2 contain malware?
No malware was identified in github.com/klauspost/cpuid/v2@v2.2.9 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/klauspost/cpuid/v2 checked?
Togoder Security downloaded the published Go package and had an AI model read its 11 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/klauspost/cpuid/v2 together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/klauspost/cpuid/v2@v2.2.9, cost nothing.