Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
DPRK-linked actors planted Go malware in HashiCorp Terraform providers and Go modules.
Aikido said Go malware was distributed through HashiCorp Registry Terraform providers gocommunity-io/dockerd (222 downloads) and kreuzwenker/docker (1,449 downloads), plus Go modules gocommunity.io/orderedbtree and gogets.dev/btreex. The payloads overlap Graphalgo, a campaign ReversingLabs attributed to North Korean operators that approaches developers with fake Web3 jobs and malicious dependencies. The Go implant checks in over Slack, polls an Ethereum contract on Arbitrum Sepolia, collects system details, and can execute Go or JavaScript commands. Researchers also flagged related npm packages, and SentinelOne separately described TraderTraitor using weaponized Terraform lock files.