< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-09-23T23:36:30+05:30

Malicious Terraform Providers Exploit HashiCorp Registry to Distribute Go-Based Malware

Attackers distributed Go-based malware through malicious Terraform providers and Go modules on HashiCorp Registry, leveraging blockchain and Slack for command-and-control. The campaign, linked to North Korean threat actors, employs sophisticated supply chain tactics including fake job offers and encrypted payloads.

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.

According to Aikido, the list of Terraform providers and Go modules is below -

gocommunity-io/dockerd (222 downloads) kreuzwenker/

Read original article

*** END OF TRANSMISSION ***