Attackers Leverage Malicious Terraform Providers to Distribute Go Malware via HashiCorp Registry
Researchers have identified Go‑based malware delivered through two Terraform providers and two Go modules on HashiCorp’s public registry, marking the first known use of the platform for malicious payload distribution.
Written and published by the Wepro Technology team
The Hacker News reported that cybersecurity researchers have uncovered a new supply‑chain threat in which Go‑written malware is being distributed via the HashiCorp Registry, the central repository for Terraform providers and Go modules. This is the first documented instance of threat actors using the registry as a vector for malicious payloads, raising concerns for organisations that rely on Infrastructure‑as‑Code tools.
The malicious code is hidden in two Terraform providers and two Go modules. The providers identified are gocommunity‑io/dockerd, which has recorded 222 downloads, and a package under the kreuzwenker namespace. Both were found to contain Go binaries that, when executed, download additional payloads and establish persistence on compromised systems. The researchers noted that the modules appear legitimate at first glance, making detection difficult without thorough code review.
Terraform is widely adopted in Australian enterprises and government agencies for automating cloud infrastructure, and its popularity makes it an attractive target for supply‑chain attacks. When a compromised provider is referenced in a Terraform configuration, the malicious code can be pulled automatically during the plan or apply phases, potentially affecting any environment that trusts the registry’s contents. This underscores the need for Australian IT teams to scrutinise third‑party providers before inclusion in production pipelines.
Mitigation steps include pinning provider versions, verifying checksums, and employing a private registry or proxy that can audit packages before they are consumed. Security teams should also monitor network traffic for unexpected outbound connections from build servers and enforce least‑privilege principles for Terraform execution roles. The Australian Cyber Security Centre (ACSC) recommends incorporating software‑bill‑of‑materials (SBOM) checks and regular vulnerability scanning of IaC assets to reduce exposure.
For professionals seeking to strengthen their cloud‑security skills, Wepro Technology offers courses such as Security+ and Network+ that cover best practices for protecting infrastructure‑as‑code environments. Upskilling in these areas can help Australian organisations build more resilient DevOps pipelines and defend against emerging supply‑chain threats.
Stay ahead in IT
Join 200+ Australian IT professionals getting weekly insights delivered to their inbox.
- Weekly IT news & insights
- New course announcements
- Free quiz updates
Your email
No spam, ever · Unsubscribe anytime