Malicious Terraform Providers on HashiCorp Registry Deliver Go Malware, Exposing Supply‑Chain Risk
What Happened — Researchers identified four malicious packages (two Terraform providers and two Go modules) published to the official HashiCorp Registry. The packages contain Go‑based malware that executes when users download and run the providers in their infrastructure‑as‑code pipelines.
Why It Matters for Trust & Control Assurance
- This scenario exemplifies a supply‑chain compromise that a continuous control‑assurance program must detect, document, and remediate.
- Demonstrates the need for ongoing third‑party risk monitoring and verifiable evidence that only vetted components are used in IaC workflows.
- Highlights the importance of maintaining a defensible audit trail for all external code dependencies.
Who Is Affected – Cloud‑infrastructure teams, DevOps engineers, SaaS providers, and any organization that consumes Terraform providers from public registries.
Recommended Actions –
- Inventory all Terraform providers and Go modules in use; cross‑check against known‑good sources.
- Implement automated scanning of IaC dependencies for malicious signatures and provenance verification.
- Enforce a policy that requires cryptographic signing or checksum validation for all third‑party packages.
Source: The Hacker News
Technical Notes – The malicious code is written in Go and is delivered via the standard terraform init process. No CVE is associated; the attack leverages the trust placed in the HashiCorp Registry as a centralized distribution point. Source: same