Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Researchers uncovered Go-based malware distributed through two Go Modules and two Terraform providers, marking the first known abuse of HashiCorp’s centralized repository as a malware delivery channel. The activity overlaps with Graphalgo and other North Korea-linked campaigns that use fake job offers, npm, PyPI, Slack, and blockchain-based command channels to target developers and distribute payloads. #Graphalgo #HashiCorp #Terraform #GoModules #Aikido #DPRK #PolinRider #ContagiousInterview

Keypoints

  • Go malware was delivered through two Go Modules and two Terraform providers.
  • This is the first known malicious use of HashiCorp’s centralized repository for payload distribution.
  • The campaign overlaps with Graphalgo and other DPRK-linked operations.
  • Attackers use fake Web3 job offers and developer interviews to lure victims.
  • The malware uses Slack and blockchain-based C2 channels to issue encrypted commands.

Read More: https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html