Hackers Abuse Trusted Terraform Workflows to Infect Developer Systems With Cross-Platform Malware
A newly identified supply-chain campaign is abusing Terraform provider workflows to infect developer systems with malware built for macOS, Linux, and Windows. The activity uses a trojanized Terraform provider that appears to be a legitimate AWS-related plugin, allowing it to run malicious code...