Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.
According to Aikido, the list of Terraform providers and Go modules is below -
The malware deployed through these packages demonstrates overlaps with Graphalgo, a campaign that was first documented by ReversingLabs earlier this February and attributed to North Korean (aka DPRK) threat actors.
As part of this effort, prospective developers are approached via social platforms like LinkedIn and Facebook, or through job offerings on forums by posing as non-existent Web3 companies, and then asked to complete a coding task by providing a benign GitHub repository that introduces the malicious behavior via a dependency published on npm or PyPI.
It's worth noting that the latest discovery coincides with the identification of a new set of malicious npm packages as recently as this week for delivering the same malware. A list of some of the flagged packages, as highlighted by Checkmarx, JFrog, and SafeDep, is as follows -
An analysis of these packages shows that, in some cases, the malware execution is triggered only when a specific cryptographic operation is performed, exhibiting all hallmarks of a targeted operation.
"The payload decrypts only when the victim solves a linear system with one specific matrix, takes its orders from a smart contract on the Ethereum Sepolia testnet, keeps a second command channel open over Slack, and hides behind download counts manufactured by a farm of GitHub Actions workers," JFrog said.
Source link







