Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Summary
Threat actors are exploiting the HashiCorp registry, a centralized repository for Terraform providers and Go modules, to distribute Go-based malware. Researchers identified malicious payloads within two Go modules and two Terraform providers, marking a new distribution vector for attackers.
IFF Assessment
The discovery of new methods for distributing malware to infrastructure as code tools represents a significant threat to defenders.
Defender Context
This incident highlights the growing risk of supply chain attacks targeting infrastructure as code tools. Defenders should carefully vet and scan all third-party Terraform providers and Go modules before integrating them into their pipelines, and implement strict access controls and monitoring for their development environments.