Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: iac (1 article)Clear

Attackers plant Go malware in HashiCorp Terraform registry in first such supply chain abuse

Aikido disclosed Go-based malware distributed through two Go modules and two Terraform providers, the first time attackers have used HashiCorp's centralized registry as a distribution vector. The flagged items include kreuzwenker/docker, with 1,449 downloads, and gocommunity-io/dockerd, alongside two Go modules. The malware overlaps with the Graphalgo campaign that ReversingLabs attributed to North Korean actors in February, in which developers are approached on LinkedIn, Facebook, or job forums by fake Web3 companies and asked to run a benign repository that pulls the malicious behavior from a dependency. The discovery coincides with a fresh batch of malicious npm and PyPI packages delivering the same threat, flagged by Checkmarx, JFrog, and SafeDep.

Check
Vet Terraform providers and Go modules by publisher and source, pin and review versions, and scan developer machines for the flagged packages and modules.
Affected
Developers pulling the malicious Terraform providers or Go modules, or the paired npm and PyPI packages, execute Go malware tied to the Graphalgo campaign.
Fix
Restrict registries to vetted providers, enforce allowlists for infrastructure-as-code sources, and treat unsolicited coding tasks from recruiters as supply chain risk.