importantSYS.SOURCE: The Hacker News• 2026-09-23T23:36:30+05:30
Malicious Terraform Providers Exploit HashiCorp Registry to Distribute Go-Based Malware
Attackers distributed Go-based malware through malicious Terraform providers and Go modules on HashiCorp Registry, leveraging blockchain and Slack for command-and-control. The campaign, linked to North Korean threat actors, employs sophisticated supply chain tactics including fake job offers and encrypted payloads.
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.
According to Aikido, the list of Terraform providers and Go modules is below -
gocommunity-io/dockerd (222 downloads) kreuzwenker/
*** END OF TRANSMISSION ***