Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Researchers at Aikido disclosed Go-based malware distributed through two Go modules and two Terraform providers in HashiCorp's centralized registry. It marks the first time threat actors have used the HashiCorp repository as a distribution vector for malicious payloads.
- Go malware was delivered via two Go modules and two Terraform providers
- One provider, gocommunity-io/dockerd, was downloaded 222 times
- First known abuse of the HashiCorp registry as a malware distribution vector
Read next
Security