HashiCorp Registry Abuse Extends the Graphalgo Campaign
Aikido found two malicious Terraform providers and two Go modules in the HashiCorp provider registry and public Go registries delivering Graphalgo-linked Go malware, marking a shift to centralized registry infrastructure as a delivery path. The campaign is tied to North Korean operators and to fake Web3 recruiting efforts that steer targets toward coding tasks and dependency-based payloads.
The packages look like ordinary providers or modules, so normal install and test workflows can pull them in without raising suspicion. In some samples, the malware waits until a specific cryptographic operation happens before it decrypts and runs, which means a clean-looking download or low install count does not rule out compromise.
For teams that consume registry-hosted dependencies or review outside code, the exposure is not just the named packages but the trust placed in contributor and dependency workflows. If those channels are part of your build or hiring pipeline, the registry itself can become the delivery mechanism.