Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.

According to Aikido, the list of Terraform providers and Go modules is below –

gocommunity-io/dockerd (222 downloads)
kreuzwenker/

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

It’s so hard to finish an idea that is not yours (and suggested by AI)

It’s so hard to finish an idea that is not yours (and suggested by AI) Source: Hacker News

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens New research shows content inside an email can escape its message boundary and interfere with the webmail interface.

Show HN: Sokoban AI Solver

Show HN: Sokoban AI Solver Source: Hacker News