Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.

According to Aikido, the list of Terraform providers and Go modules is below –

gocommunity-io/dockerd (222 downloads)
kreuzwenker/

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Show HN: Hacker News, Without AI

Show HN: Hacker News, Without AI Source: Hacker News

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform,

Apertus – Open Foundation Model for Sovereign AI

Apertus – Open Foundation Model for Sovereign AI Source: Hacker News