Security
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
The Hacker News·September 23, 2026·1 min read
Researchers at Aikido disclosed Go-based malware distributed via two Go Modules and two Terraform providers on the HashiCorp Registry, marking the first time the centralized repository is used as a distribution vector. The malicious providers, including gocommunity-io/dockerd with 222 downloads, deliver payloads to unsuspecting users. Organizations are advised to audit their dependencies.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
