MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-23 · via The Hacker News

Go Malware Delivered via Malicious Terraform Providers and Go Modules

Image via The Hacker News
Image via The Hacker News

Researchers at Aikido discovered Go-based malware distributed through two Go Modules and two Terraform providers on the HashiCorp registry. This marks the first time the centralized repository has been used to deliver malicious payloads. The malicious packages include gocommunity-io/dockerd and kreuzwenker/ among others.

Expanded Detail

This incident highlights a growing trend in software supply chain attacks, where trusted repositories are exploited to distribute malicious code. The discovery of Go-based malware within both Go Modules and Terraform providers on the HashiCorp registry suggests that attackers are increasingly targeting developer tools and infrastructure-as-code ecosystems. Because these platforms are widely used for automation and deployment, a compromised package can potentially reach many downstream systems. The researchers' identification of specific malicious packages underscores the need for heightened vigilance when integrating third-party dependencies, even from official registries. This case may prompt more rigorous security screening and community reporting mechanisms across similar centralized repositories.

Context

The impact could be significant for development teams and organizations relying on Terraform or Go modules, as a single malicious dependency might compromise build pipelines or cloud infrastructure. Smaller firms with limited security resources may be especially vulnerable, potentially facing data breaches or operational disruptions. However, the early detection by researchers may limit real-world damage, and increased awareness could lead to stronger vetting practices industry-wide. Ultimately, this story may serve as a cautionary example, reinforcing that trust in official registries must be balanced with proactive verification.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
Supply-Chain Attack on MemTensor Packages Delivers Cross-Platform Credential Stealer · Cybersecurity
Developer documentation placeholder domain weaponized for ClickFix malware campaign · Cybersecurity
RemControl Android trojan spreads via fake IPTV app, steals banking data across Europe and Canada · Cybersecurity
AI-Powered Malware 'ClosedQuorum' Automates Post-Compromise Actions on Windows · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry.” Browse more stories.