AI Weekly Malaysia

Back to items Summaries

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

ID
27871
Status
summarized
Published
24 Sep 2026, 2:06 AM
Fetched
24 Sep 2026, 4:22 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.0
Created
24 Sep 2026, 4:25 AM
Tags
Audience
developersvibe_coderssaas_startup_founders

What happened

Researchers at Aikido discovered the first malicious Terraform providers distributed via HashiCorp's registry, alongside Go modules and npm packages, delivering Go-based malware linked to DPRK threat actors (Graphalgo campaign). The attack uses fake Web3 job offers on LinkedIn and Facebook to trick developers into cloning repositories with malicious dependencies; the payload only decrypts when a specific cryptographic operation is performed, takes C2 orders from an Ethereum Sepolia testnet smart contract, and uses Slack as a secondary command channel.

Why it matters

If you use Terraform providers from HashiCorp's registry or pull Go modules, audit your dependencies now for gocommunity-io/dockerd, kreuzwenker/docker, gocommunity.io/orderedbtree, and gogets.dev/btreex. Treat unsolicited coding tasks from 'Web3 companies' on LinkedIn as a known attack vector — the social engineering pattern here is specific and active, not theoretical.

Discussion angle

How many of us actually verify Terraform provider provenance or Go module checksums before running `terraform init` or `go mod tidy`? This is the first documented abuse of HashiCorp's registry — discuss what minimum dependency hygiene looks like for teams using IaC.

Top