
highMalware
Malicious Terraform Providers Distribute Go Malware via HashiCorp Registry
Security researchers have identified a campaign in which threat actors uploaded malicious Terraform providers and Go modules to the HashiCorp provider registry and Go module proxy, respectively. The actors leveraged these trusted channels to distribute Go-based malware targeting container environments and orchestration platforms. This marks the first observed use of the HashiCorp registry as a distribution vector for malicious payloads, exploiting the trust users place in officially indexed providers and modules.
The Hacker News1 min read