Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.

According to Aikido, the list of Terraform providers and Go modules is below –

gocommunity-io/dockerd (222 downloads)
kreuzwenker/

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit Read on The Hacker News Source: The Hacker News

Linux on the Atari Jaguar. No, really.

Linux on the Atari Jaguar. No, really. Source: Hacker News

Who Gets to Define the Rules for AI?

Who Gets to Define the Rules for AI? Source: Hacker News