Malicious Terraform Providers Seeded Through HashiCorp Registry
5 Articles
5 Articles
Malicious Terraform providers seeded through HashiCorp Registry
Attackers uploaded malicious Terraform providers to the HashiCorp Registry to deliver Go-based malware through infrastructure-as-code workflows. The activity weaponizes trusted provider distribution paths, turning routine Terraform pulls into an...
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below gocommunity-io/dockerd (222 downloads) kreuzwenker/
The Malware Hiding in Developer Tools That Turned Terraform Providers Into Attack Paths
Malware has moved into tools developers use to build and manage cloud infrastructure. A campaign linked to Graphalgo planted a remote access program in Terraform providers and Go software packages, turning routine development work into a possible route onto valuable machines. The packages did not behave like obvious malicious downloads. Some waited for particular inputs […]
Coverage Details
Bias Distribution
- 100% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium







