Vendor
TraderTraitor Campaign Targeting DevOps Engineers via Weaponized Terraform Repositories
4 TTPs 5 IOCsNorth Korean threat actor TraderTraitor is using fake job interview lures on GitHub containing weaponized Terraform lock files to deliver macOS backdoors to DevOps engineers, facilitating cloud credential theft.
HashiCorp Terraform Information Disclosure and Security Bypass
1 TTPA local vulnerability in HashiCorp Terraform identified as CVE-2024-7956 allows local attackers to bypass security controls and access sensitive configuration information.
Privilege Escalation in HashiCorp Vault Secrets Operator
1 TTP 1 CVEA vulnerability in the HashiCorp Vault Secrets Operator allows a remote, authenticated attacker to escalate privileges, leading to potential unauthorized data disclosure or manipulation within Kubernetes environments.
Security Updates for HashiCorp Consul
1 IOCHashiCorp has released security advisory HCSEC-2026-25 addressing multiple vulnerabilities in Consul Community Edition and Consul Enterprise that require immediate patching.
Shai-Hulud Campaign Activity
20 IOCsTracking brief for the Shai-Hulud campaign; individual sightings are folded in as reported.
Hashicorp Terraform: Information Disclosure Vulnerability
1 TTPA vulnerability in Hashicorp Terraform allows a remote, authenticated attacker to disclose sensitive information, which could lead to the exposure of confidential data.
Malicious @beproduct/nestjs-auth Package Contains Mini Shai-Hulud Worm (CVE-2026-46412)
2 rules 4 TTPs 6 IOCsBetween May 11th and May 12th of 2026, a threat actor compromised an npm publish token to publish 18 malicious versions of the '@beproduct/nestjs-auth' package (versions 0.1.2 through 0.1.19) containing payloads from the Mini Shai-Hulud npm supply-chain worm campaign that exfiltrated npm tokens, GitHub PATs/OAuth tokens, AWS credentials, and Vault tokens, impacting developer environments.