Malware turns up in HashiCorp Terraform registry packages

Aikido traced Go malware inside two Terraform providers and two Go modules, the first abuse of HashiCorp's registry as a distribution channel.

CSBadmin
2 Min Read

HashiCorp’s registry has been turned into a malware delivery route. Aikido found a Go implant tucked inside two Terraform providers and two Go modules, the first time the central repository has been abused this way.

The activity is attributed to the cluster behind Graphalgo, a campaign documented by ReversingLabs in February and linked to North Korean operators. The flagged artifacts include the providers gocommunity-io/dockerd and kreuzwenker/docker, plus the modules gocommunity.io/orderedbtree and gogets.dev/btreex.

Getting the code onto a machine still relies on the same old flattery. Invented Web3 firms reach out on LinkedIn, Facebook and job forums with a paid task and a clean-looking GitHub repo, and the payload rides in on a dependency fetched from npm or PyPI.

The Go port keeps the same blockchain and Slack command channels as its npm sibling. It polls an Ethereum smart contract on the Arbitrum Sepolia testnet every three seconds for encrypted orders, executes them as Go or JavaScript, and opens a second channel through a Slack bot token. Infected hosts can act as relays for one another without the operator exposing the channel.

A second report from CloudSEK covers a loader it names GHAPPIER, delivered through a hijacked npm package, @dforge-core/dforge-mcp. The poisoned build survived only 35 minutes on September 9 before the maintainer reverted it. By the time attention faded, that loader had surfaced in 65 repositories spread over 22 accounts.

Maintainers of the Rust language, meanwhile, were told to treat video-call job interviews as hostile ground, a tactic that echoes the Contagious Interview campaign run from North Korea.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.