Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: hashicorp (2 articles)Clear

Attackers plant Go malware in HashiCorp Terraform registry in first such supply chain abuse

Aikido disclosed Go-based malware distributed through two Go modules and two Terraform providers, the first time attackers have used HashiCorp's centralized registry as a distribution vector. The flagged items include kreuzwenker/docker, with 1,449 downloads, and gocommunity-io/dockerd, alongside two Go modules. The malware overlaps with the Graphalgo campaign that ReversingLabs attributed to North Korean actors in February, in which developers are approached on LinkedIn, Facebook, or job forums by fake Web3 companies and asked to run a benign repository that pulls the malicious behavior from a dependency. The discovery coincides with a fresh batch of malicious npm and PyPI packages delivering the same threat, flagged by Checkmarx, JFrog, and SafeDep.

Check
Vet Terraform providers and Go modules by publisher and source, pin and review versions, and scan developer machines for the flagged packages and modules.
Affected
Developers pulling the malicious Terraform providers or Go modules, or the paired npm and PyPI packages, execute Go malware tied to the Graphalgo campaign.
Fix
Restrict registries to vetted providers, enforce allowlists for infrastructure-as-code sources, and treat unsolicited coding tasks from recruiters as supply chain risk.

Critical Terraform MCP flaw lets one user's cloud token serve another's requests

HashiCorp, Veeam, and Django patched critical flaws the same week, led by a top-severity bug in HashiCorp's Terraform MCP Server, which connects AI assistants to Terraform. Tracked as CVE-2026-16498 and scored 10.0, it is a cross-tenant flaw in the server's multi-user HTTP mode: its cache looked up clients by session identifier alone, without binding a cached client to the token that created it, so anyone who obtained another user's session ID could run Terraform actions with that user's credential. Only the shared HTTP deployment is affected, not local single-user mode. Veeam separately fixed an unauthenticated console flaw exposing agent credentials, and Django a code-execution bug in spatial queries.

Check
Update Terraform MCP Server to 1.1.0 or later, Veeam Service Provider Console to 9.3.0.35057, and Django to 6.0.8 or 5.2.17, prioritizing multi-user Terraform MCP deployments.
Affected
Teams running Terraform MCP Server in shared HTTP mode (CVE-2026-16498), Veeam Service Provider Console, or affected Django; the Terraform flaw lets one tenant's token be reused for another's requests.
Fix
Patch all three, run MCP servers in single-user stdio mode where possible, bind sessions to their credentials, restrict access to shared MCP HTTP listeners, and rotate tokens that may have been reused.