{"id":1963,"date":"2026-09-24T14:34:24","date_gmt":"2026-09-24T09:04:24","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1963"},"modified":"2026-09-28T10:27:51","modified_gmt":"2026-09-28T04:57:51","slug":"malicious-terraform-providers-deliver-go-malware-via-hashicorp","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/","title":{"rendered":"Malicious Terraform Providers Deliver Go Malware via HashiCorp"},"content":{"rendered":"<p>Attackers have used malicious Terraform providers to push Go-based malware through the HashiCorp Terraform Registry. Researchers at Aikido reported this as the first confirmed case of the centralized registry serving as a malware distribution channel. Two Terraform providers and two Go modules carried the payload.<\/p>\n<p>The malware shares blockchain and Slack infrastructure with Graphalgo, a campaign that ReversingLabs first documented earlier this year and that researchers have tied to North Korean<a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-threat-actor-in-cyber-security\/\"> threat actors<\/a>. The shift into infrastructure-as-code tooling matters operationally. Terraform providers execute during provisioning workflows, often on hosts that already hold cloud credentials, source access, and deployment secrets.<\/p>\n<p>For DevOps and security teams, this changes where they need to review dependency risk. Code-review discipline built for application dependencies now needs to extend to infrastructure tooling.<\/p>\n<h2>Two Terraform providers and two Go modules carried the payload<\/h2>\n<p>Aikido identified four packages carrying the <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-malware\/\">malware<\/a>:<\/p>\n<ul>\n<li>gocommunity-io\/dockerd \u2014 Terraform provider, 222 downloads<\/li>\n<li>kreuzwenker\/docker \u2014 Terraform provider, 1,449 downloads. This is a typosquat of the legitimate kreuzwerker\/docker provider, which has 56 million reported downloads. The two names differ by a single letter, &#8216;n&#8217; in place of &#8216;r,&#8217; the kind of mistake a developer makes when typing a provider name from memory.<\/li>\n<li>gocommunity.io\/orderedbtree \u2014 Go module, published August 11. Aikido found the malware shipped here in plaintext, with no encryption or compression to hide it.<\/li>\n<li>gogets.dev\/btreex \u2014 Go module, published September 8. This one hid its payload inside a ZIP archive disguised as a SQL file. The threat actor also forged commit history, backdating it to November 2025 to make the package look more established than it was.<\/li>\n<\/ul>\n<p>Terraform providers run as plugins during infrastructure provisioning. That execution context often includes cloud credentials, repository access, and CI secrets. A malicious provider therefore reaches privileged material more directly than a typical application dependency does. Aikido noted the campaign is also expanding its reach beyond npm and PyPI, the ecosystems where this <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-a-malware-family\/\">malware family<\/a> first appeared.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/threat-classification.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>What is Threat Classification?<\/h4><p>How threat classification, severity, and Hexnode XDR streamline endpoint incident response.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/what-is-threat-classification\/\" aria-label=\"What is Threat Classification?\"><\/a><\/div><\/div><\/div>\n<h2>Two separate communication channels, not one<\/h2>\n<p>The Go version of the malware, ported from the npm implant, retains its dual command-and-control design. These are two distinct mechanisms, and reviewed sources describe them separately.<\/p>\n<p>Before either channel activates, the malware stays inert. In the Terraform providers, the malicious code is hidden inside <code>resource_docker_container_funcs.go<\/code> and only runs when the SHA256 hash of the <code>containerName<\/code> and <code>networkID<\/code> input variables, concatenated together, matches a hardcoded value. Without that exact match, the payload never executes. This is why automated sandbox analysis, which typically runs generic or randomized test inputs, missed the malware. The sandbox simply never supplied the specific values needed to trigger it.<\/p>\n<h3>Blockchain dead drop<\/h3>\n<p>The malware polls a hard-coded Ethereum smart contract on the Arbitrum Sepolia testnet every three seconds for encrypted commands. Researcher Oliver Smith said the malware generates an ephemeral key pair, then combines it with two threat-actor public keys to derive shared keys. This lets infected hosts communicate without exposing C2 traffic to other infected clients. Commands execute as Go or JavaScript.<\/p>\n<h3>Slack side channel<\/h3>\n<p>The implant separately polls Slack&#8217;s conversations.history endpoint every 10 seconds using a bot token. It reads packet types (start, chunk, end) to reassemble file transfers delivered over Slack.<\/p>\n<p>Socket researcher Karlo Zanki said execution appears gated by data supplied through a front-end component, which likely hinders analysis rather than indicating narrow targeting alone.<\/p>\n<h2>Part of a broader, still-forming pattern<\/h2>\n<p>Developers are lured via fake job offers, overlapping with Contagious Interview tactics. TraderTraitor separately used weaponized Terraform lock files for different Rust backdoors. Researchers call this pattern still unconfirmed.<\/p>\n<h3>Compromised packages at a glance<\/h3>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 23.1501%; text-align: left;\"><strong>Package<\/strong><\/th>\n<th style=\"width: 37.9493%; text-align: left;\"><strong>Type<\/strong><\/th>\n<th style=\"width: 37.8436%; text-align: left;\"><strong>Operational Priority<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 23.1501%;\">kreuzwenker\/docker<\/td>\n<td style=\"width: 37.9493%;\">Terraform provider (1,449 downloads)<\/td>\n<td style=\"width: 37.8436%;\">Highest exposure; audit every pipeline that pulled this provider<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.1501%;\">gocommunity-io\/dockerd<\/td>\n<td style=\"width: 37.9493%;\">Terraform provider (222 downloads)<\/td>\n<td style=\"width: 37.8436%;\">Confirm removal from any Terraform configuration referencing it<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.1501%;\">gocommunity.io\/orderedbtree<\/td>\n<td style=\"width: 37.9493%;\">Go module<\/td>\n<td style=\"width: 37.8436%;\">Review dependent Go projects for inclusion<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.1501%;\">gogets.dev\/btreex<\/td>\n<td style=\"width: 37.9493%;\">Go module<\/td>\n<td style=\"width: 37.8436%;\">Review dependent Go projects for inclusion<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Where endpoint controls fit in<\/h2>\n<p>Terraform providers and Go modules run directly on developer and DevOps endpoints, so endpoint-level controls still have a role to play. Here&#8217;s what Hexnode UEM and XDR can and can&#8217;t do in this scenario.<\/p>\n<h3>Hexnode UEM<\/h3>\n<ul>\n<li>Application blocklisting and allowlisting\u00a0 &#8211; Available on Windows, macOS, Linux, iOS, Android, tvOS, and Fire OS endpoints. Lets administrators restrict unapproved development tools on developer machines.<\/li>\n<li>Non-compliance flagging &#8211; <a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> flags devices where blocklisted software appears, giving admins a signal to investigate.<\/li>\n<\/ul>\n<h3>Hexnode XDR<\/h3>\n<ul>\n<li>Windows and macOS coverage &#8211; <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> can investigate suspicious activity on managed Windows and macOS endpoints, giving security teams a starting point for containment on those platforms.<\/li>\n<li>Scope limit &#8211; This is endpoint-level investigation, not detection of a specific malware family or implant.<\/li>\n<\/ul>\n<h3>What Hexnode does not cover:<\/h3>\n<ul>\n<li>Detecting this specific malware family or the Graphalgo implant<\/li>\n<li>Patching the compromised Terraform providers or Go modules<\/li>\n<li>Monitoring CI\/CD pipeline logs, registry activity, or blockchain traffic<\/li>\n<\/ul>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center>Endpoint controls complement, but don&#8217;t replace, the credential rotation, dependency review, and registry-level scrutiny that affected teams and HashiCorp itself must handle directly.<\/p>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Was the HashiCorp Terraform Registry itself breached?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Reviewed sources describe attackers publishing malicious packages under their own namespaces, not compromising the registry&#8217;s infrastructure.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How is this different from typical npm or PyPI supply chain attacks?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Terraform providers execute during infrastructure provisioning, often with direct access to cloud credentials and deployment permissions that standard application dependencies don&#8217;t carry.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Should teams stop using third-party Terraform providers?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Not necessarily. Verify publisher identity, pin exact versions, and review what credentials a provider&#8217;s execution context can reach before adopting it.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity framework\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-300x225.png?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-768x576.png?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity framework\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Building a cybersecurity framework for your enterprise\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Explore key cybersecurity frameworks and how UEM strengthens organizational defenses against network penetration attacks.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/building-a-cybersecurity-framework-for-your-enterprise\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h3>Conclusion<\/h3>\n<p>This campaign shows that infrastructure-as-code dependencies now sit inside the same trust boundary as production code. A malicious Terraform provider can reach cloud credentials and deployment privileges that most application dependencies never touch.<\/p>\n<p>Security teams should treat unfamiliar or low-adoption Terraform providers and Go modules with the same scrutiny applied to production code, and extend endpoint and credential hygiene to developer and CI\/CD environments accordingly.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Infrastructure dependencies are executable trust boundaries. <\/h5><p>Get operational threat briefings like this one delivered to your inbox. <\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Attackers have used malicious Terraform providers to push Go-based malware through the HashiCorp Terraform Registry&#8230;.<\/p>\n","protected":false},"author":5,"featured_media":1970,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[14,15],"class_list":["post-1963","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-supply-chain-attack","category-malware","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Malicious Terraform Providers Deliver Go Malware via HashiCorp<\/title>\n<meta name=\"description\" content=\"Malicious Terraform providers on HashiCorp Registry deliver Go malware linked to Graphalgo via blockchain and Slack for command and control.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Malicious Terraform Providers Deliver Go Malware via HashiCorp\" \/>\n<meta property=\"og:description\" content=\"Malicious Terraform providers on HashiCorp Registry deliver Go malware linked to Graphalgo via blockchain and Slack for command and control.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-24T09:04:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-28T04:57:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/malicious-terraform-providers.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"Malicious Terraform Providers Deliver Go Malware via HashiCorp\",\"datePublished\":\"2026-09-24T09:04:24+00:00\",\"dateModified\":\"2026-09-28T04:57:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\\\/\"},\"wordCount\":1063,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/malicious-terraform-providers.jpeg?format=webp\",\"articleSection\":[\"Supply Chain Attack\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\\\/\",\"name\":\"Malicious Terraform Providers Deliver Go Malware via HashiCorp\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/malicious-terraform-providers.jpeg?format=webp\",\"datePublished\":\"2026-09-24T09:04:24+00:00\",\"dateModified\":\"2026-09-28T04:57:51+00:00\",\"description\":\"Malicious Terraform providers on HashiCorp Registry deliver Go malware linked to Graphalgo via blockchain and Slack for command and control.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/malicious-terraform-providers.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/malicious-terraform-providers.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"malicious terraform providers\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Malicious Terraform Providers Deliver Go Malware via HashiCorp\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"description\":\"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Malicious Terraform Providers Deliver Go Malware via HashiCorp","description":"Malicious Terraform providers on HashiCorp Registry deliver Go malware linked to Graphalgo via blockchain and Slack for command and control.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/","og_locale":"en_US","og_type":"article","og_title":"Malicious Terraform Providers Deliver Go Malware via HashiCorp","og_description":"Malicious Terraform providers on HashiCorp Registry deliver Go malware linked to Graphalgo via blockchain and Slack for command and control.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-24T09:04:24+00:00","article_modified_time":"2026-09-28T04:57:51+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/malicious-terraform-providers.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"Malicious Terraform Providers Deliver Go Malware via HashiCorp","datePublished":"2026-09-24T09:04:24+00:00","dateModified":"2026-09-28T04:57:51+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/"},"wordCount":1063,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/malicious-terraform-providers.jpeg?format=webp","articleSection":["Supply Chain Attack","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/","url":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/","name":"Malicious Terraform Providers Deliver Go Malware via HashiCorp","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/malicious-terraform-providers.jpeg?format=webp","datePublished":"2026-09-24T09:04:24+00:00","dateModified":"2026-09-28T04:57:51+00:00","description":"Malicious Terraform providers on HashiCorp Registry deliver Go malware linked to Graphalgo via blockchain and Slack for command and control.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/malicious-terraform-providers.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/malicious-terraform-providers.jpeg?format=webp","width":1340,"height":700,"caption":"malicious terraform providers"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/malicious-terraform-providers-deliver-go-malware-via-hashicorp\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Malicious Terraform Providers Deliver Go Malware via HashiCorp"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"description":"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1963","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1963"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1963\/revisions"}],"predecessor-version":[{"id":2011,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1963\/revisions\/2011"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1970"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1963"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1963"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}