← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 23, 2026 · 18:06via The Hacker News

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Brief

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.

According to Aikido, the list of Terraform providers and Go modules is below -

gocommunity-io/dockerd (222 downloads) kreuzwenker/

Read more on The Hacker News