Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Researchers uncover malicious Terraform providers and Go modules delivering Graphalgo-linked Go malware using Slack and Ethereum blockchain infrastructure for command and control.

Cybersecurity researchers have discovered a software supply-chain campaign using malicious Terraform providers and Go modules to distribute Go-based malware, expanding an operation previously associated with poisoned npm packages.
Aikido identified two malicious community Terraform providers distributed through the public HashiCorp Terraform Registry, marking the first time its researchers have observed malware being delivered through Terraform providers. The malware overlaps with the Graphalgo campaign previously linked by researchers to North Korea-associated threat activity.
Malicious Packages Identified
| Ecosystem | Package | Reported Downloads |
|---|---|---|
| Terraform | gocommunity-io/dockerd |
222 |
| Terraform | kreuzwenker/docker |
1,449 |
| Go Module | gocommunity.io/orderedbtree |
— |
| Go Module | gogets.dev/btreex |
— |
Terraform providers are plugins that Terraform installs to interact with infrastructure platforms and APIs. The public registry includes not only HashiCorp-maintained providers but also community providers published by individual maintainers and organizations.
How the Attack Works
The malicious Terraform providers deliver a Go port of Graphalgo malware that shares infrastructure and cryptographic elements with recent malicious JavaScript packages.
The infection flow can be summarized as:
Developer Installs Malicious Provider → Go Malware Executes → System Reconnaissance → Slack Check-In → Blockchain C2 → Encrypted Commands → Go/JavaScript Execution
Once running, the malware collects information including:
- Operating system
- Hostname
- Hardware information
- Node.js availability
The information is transmitted to an attacker-controlled Slack channel through its API.
Blockchain and Slack Used for C2
The malware uses two unusual command-and-control mechanisms.
One channel uses a Slack bot token, while the second uses an Ethereum smart contract on the Arbitrum Sepolia testnet as a blockchain dead drop.
The implant periodically queries the smart contract for encrypted instructions. Commands intended for a particular infected machine can then be decrypted and executed as Go or JavaScript code.
The malware also generates an ephemeral public/private key pair and combines it with attacker-controlled public keys to establish shared encryption keys, helping separate communications between infected systems.
Possible Connection to Fake Job Interviews
Researchers noted similarities with the Graphalgo operation, in which developers were approached through LinkedIn, Facebook, forums and fake Web3 job opportunities.
Victims could be asked to complete coding assignments containing malicious dependencies, turning what appears to be a legitimate technical interview into an infection vector. Researchers have linked the broader Graphalgo activity to North Korea-associated threat actors, although they caution that it is still too early to conclude that Terraform registries have become a standard distribution method for those actors.
Why Terraform Providers Are Attractive Targets
Terraform commonly operates close to sensitive infrastructure and may have access to:
- Cloud credentials
- Environment variables
- CI/CD secrets
- Infrastructure APIs
- Production configuration
- Service-account credentials
A malicious provider executing inside such an environment could therefore provide attackers with a valuable foothold into infrastructure-management systems.
HashiCorp notes that providers downloaded from the registry are cryptographically signed, but community providers can be self-signed, and HashiCorp does not provide the same chain of trust for them as it does for HashiCorp-signed or verified partner providers.
What Security Teams Should Do
Organizations should check Terraform configurations, dependency lock files and developer environments for the identified packages.
Security teams should also:
- Remove the malicious Terraform providers and Go modules.
- Review
terraform.lock.hclfor unexpected providers or versions. - Prefer official or verified providers where possible.
- Pin provider versions rather than automatically accepting newer releases.
- Review CI/CD environments for suspicious Terraform executions.
- Investigate unexpected Slack API and blockchain RPC connections.
- Rotate cloud or infrastructure credentials potentially exposed on affected systems.
- Review developer systems involved in suspicious coding assignments or job interviews.
HashiCorp recommends constraining provider versions and committing Terraform's dependency lock file to version control so deployments consistently use expected provider releases.
Security Takeaway
This campaign demonstrates how software supply-chain attackers are expanding beyond traditional ecosystems such as npm and PyPI into Infrastructure-as-Code tooling.
Malicious Terraform Provider → Developer/CI Environment → Go Malware → Blockchain + Slack C2 → Remote Code Execution
The risk is particularly significant because Terraform often runs with access to sensitive cloud and production infrastructure credentials.
Related reporting
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Malware via ClickFix
Attackers abuse ChatGPT Custom GPTs and sponsored Google results to redirect victims to ClickFix pages that execute PowerShell and install remote access trojan malware.
Star Blizzard Targets 100+ Organizations With Fake Event Invites and CosmicPulse Backdoor
Russia-linked Star Blizzard targets more than 100 organizations using fake event invitations, the new RedFlick malware delivery technique and the CosmicPulse Windows backdoor.
101 Malicious npm Packages Secretly Add Developers to WhatsApp Groups
Researchers uncover 101 malicious npm packages in the PhantomSub campaign that abuse authenticated WhatsApp sessions to secretly add developers to attacker-controlled groups and channels.


