HackerFeeds

CyberSecurity News

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

The Hacker News
· September 23, 2026

AI summary

Cybersecurity researchers have discovered a new method of malware distribution using the HashiCorp registry. Attackers are utilizing malicious Terraform providers and Go modules to deliver Go-based malware. This is the first known instance of threat actors exploiting the centralized repository in this way. The malware was distributed via two Go modules and two Terraform providers, including gocommunity-io/dockerd, which had 222 downloads. The affected Terraform providers and Go modules were listed by researchers.

Read the full article at The Hacker Newsthehackernews.com/2026/09/attackers-use-malicious-terraform.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.