Aikido disclosed Go-based malware distributed through two Go modules and two Terraform providers, the first time attackers have used HashiCorp's centralized registry as a distribution vector. The flagged items include kreuzwenker/docker, with 1,449 downloads, and gocommunity-io/dockerd, alongside two Go modules. The malware overlaps with the Graphalgo campaign that ReversingLabs attributed to North Korean actors in February, in which developers are approached on LinkedIn, Facebook, or job forums by fake Web3 companies and asked to run a benign repository that pulls the malicious behavior from a dependency. The discovery coincides with a fresh batch of malicious npm and PyPI packages delivering the same threat, flagged by Checkmarx, JFrog, and SafeDep.