CONNECT WITH US
Cyber Security

Cyber Security

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

The Hacker News logo

Published on

Add as a preferred source on Google
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.

According to Aikido, the list of Terraform providers and Go modules is below -

The malware deployed through these packages demonstrates overlaps with Graphalgo, a campaign that was first documented by ReversingLabs earlier this February and attributed to North Korean (aka DPRK) threat actors.

As part of this effort, prospective developers are approached via social platforms like LinkedIn and Facebook, or through job offerings on forums by posing as non-existent Web3 companies, and then asked to complete a coding task by providing a benign GitHub repository that introduces the malicious behavior via a dependency published on npm or PyPI.

It's worth noting that the latest discovery coincides with the identification of a new set of malicious npm packages as recently as this week for delivering the same malware. A list of some of the flagged packages, as highlighted by Checkmarx, JFrog, and SafeDep, is as follows -

An analysis of these packages shows that, in some cases, the malware execution is triggered only when a specific cryptographic operation is performed, exhibiting all hallmarks of a targeted operation.

"The payload decrypts only when the victim solves a linear system with one specific matrix, takes its orders from a smart contract on the Ethereum Sepolia testnet, keeps a second command channel open over Slack, and hides behind download counts manufactured by a farm of GitHub Actions workers," JFrog said.


Source link

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We TheMorningPulse.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It's possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.