Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
- ID
- 27871
- Status
- summarized
- Published
- 24 Sep 2026, 2:06 AM
- Fetched
- 24 Sep 2026, 4:22 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.0
- Created
- 24 Sep 2026, 4:25 AM
- Tags
- Audience
- developersvibe_coderssaas_startup_founders
What happened
Researchers at Aikido discovered the first malicious Terraform providers distributed via HashiCorp's registry, alongside Go modules and npm packages, delivering Go-based malware linked to DPRK threat actors (Graphalgo campaign). The attack uses fake Web3 job offers on LinkedIn and Facebook to trick developers into cloning repositories with malicious dependencies; the payload only decrypts when a specific cryptographic operation is performed, takes C2 orders from an Ethereum Sepolia testnet smart contract, and uses Slack as a secondary command channel.
Why it matters
If you use Terraform providers from HashiCorp's registry or pull Go modules, audit your dependencies now for gocommunity-io/dockerd, kreuzwenker/docker, gocommunity.io/orderedbtree, and gogets.dev/btreex. Treat unsolicited coding tasks from 'Web3 companies' on LinkedIn as a known attack vector — the social engineering pattern here is specific and active, not theoretical.
Discussion angle
How many of us actually verify Terraform provider provenance or Go module checksums before running `terraform init` or `go mod tidy`? This is the first documented abuse of HashiCorp's registry — discuss what minimum dependency hygiene looks like for teams using IaC.