chiprook
← Security
SecuritySeptember 24, 2026, 01:06

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Researchers at Aikido disclosed Go-based malware distributed through two Go modules and two Terraform providers in HashiCorp's centralized registry. It marks the first time threat actors have used the HashiCorp repository as a distribution vector for malicious payloads.

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
#HashiCorp#Terraform#Go
Read next
Security

New EDR Evasion Stack Slips Process Injection Past Defenses

Security

Open-source Bharat ABIS shows potential for national-scale deduplication

Security

Watchdog: 86% of agencies missed CISA cloud security directive deadline

Security

F5 patches exploited BIG-IP APM zero-day enabling RCE