Summary
Togoder Security scanned the Go package github.com/quagmt/udecimal@v1.10.1 on Oct 5, 2026. An AI review of 6 source files produced 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
Unsafe memory manipulation
NPS-D3101D0F8BDE
The function unsafeStringToBytes uses unsafe.Slice and unsafe.StringData to reinterpret a string's underlying bytes as a mutable []byte without copying. This violates Go's string immutability and could lead to memory corruption if the returned slice is modified. It is used in MarshalJSON to return a byte slice backed by a string, which is then returned to the caller. While not overtly malicious, this is a dangerous pattern that can cause undefined behavior and is generally considered a security risk.
Potential JSON output corruption
NPS-CA163AFFDDB9
In MarshalJSON, the result of d.stringU128(true, true) is converted to a []byte via unsafeStringToBytes. The string is built in appendBuffer with a fixed-size local buffer and then copied into a new slice. However, using unsafe to convert the string back to a byte slice means the returned byte slice shares memory with the string. If the caller modifies the byte slice, it would corrupt the string, though in practice the caller (json.Marshal) typically does not. Still, it is a fragile and risky pattern.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| codec.go | medium | The code contains unsafe memory manipulation via unsafe.Slice/unsafe.StringData, which is a risky but potentially performance-motivated pattern; no overt malicious behavior detected. |
| bint.go | safe | Cleared by Jev triage; no further analysis needed |
| decimal.go | safe | Cleared by Jev triage; no further analysis needed |
| doc.go | safe | Cleared by Jev triage; no further analysis needed |
| u128.go | safe | Cleared by Jev triage; no further analysis needed |
| u256.go | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of github.com/quagmt/udecimal
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| v1.10.1 | Needs review | 6 | Oct 5, 2026 |
Frequently asked questions
Is github.com/quagmt/udecimal safe to use?
No confirmed malware was found in github.com/quagmt/udecimal@v1.10.1, but the review flagged 2 medium severity findings for risky patterns worth checking before you rely on it.
Does github.com/quagmt/udecimal contain malware?
No malware was identified in github.com/quagmt/udecimal@v1.10.1 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/quagmt/udecimal checked?
Togoder Security downloaded the published Go package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/quagmt/udecimal together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/quagmt/udecimal@v1.10.1, cost nothing.