SECURITY·중요도 8·2026. 09. 23.·The Hacker News
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
── KO ──────────────────
사이버 보안 연구원이 HashiCorp 레지스트리를 통한 Go 기반 악성코드 배포를 발표했습니다.
악성 Terraform 프로바이더를 통해 Go 기반의 악성코드가 배포되고 있습니다. 이는 HashiCorp에서 호스팅하는 중앙 집중식 레포지토리를 통해 위협 행위자들이 악성 페이로드를 배포한 첫 사례로 기록됩니다. Aikido에 따르면, 사용자들이 다운로드한 여러 Terraform 프로바이더와 Go 모듈이 이에 포함되어 있습니다.
── EN ──────────────────
Cybersecurity researchers report Go-based malware distributed via HashiCorp registry.
Researchers have disclosed the distribution of Go-based malware via Terraform providers and Go Modules. This marks the first use of HashiCorp's centralized repository by threat actors as a vector for malicious payloads. According to Aikido, a list of the affected Terraform providers and Go modules has been shared.