
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.
Summary
According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/
This is a brief wire summary — the full story (linked below) has the complete details.
KazaSec's take
Stories like this are part of why proactive security testing exists — finding the gap before someone else does is always cheaper than responding after the fact.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.