Skip to main content
The Wire
CyberNews by Zentrya One
Malware

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Researchers uncover malicious Terraform providers and Go modules delivering Graphalgo-linked Go malware using Slack and Ethereum blockchain infrastructure for command and control.

Cybersecurity researchers have discovered a software supply-chain campaign using malicious Terraform providers and Go modules to distribute Go-based malware, expanding an operation previously associated with poisoned npm packages.

Aikido identified two malicious community Terraform providers distributed through the public HashiCorp Terraform Registry, marking the first time its researchers have observed malware being delivered through Terraform providers. The malware overlaps with the Graphalgo campaign previously linked by researchers to North Korea-associated threat activity.

Malicious Packages Identified

Ecosystem Package Reported Downloads
Terraform gocommunity-io/dockerd 222
Terraform kreuzwenker/docker 1,449
Go Module gocommunity.io/orderedbtree —
Go Module gogets.dev/btreex —

Terraform providers are plugins that Terraform installs to interact with infrastructure platforms and APIs. The public registry includes not only HashiCorp-maintained providers but also community providers published by individual maintainers and organizations.

How the Attack Works

The malicious Terraform providers deliver a Go port of Graphalgo malware that shares infrastructure and cryptographic elements with recent malicious JavaScript packages.

The infection flow can be summarized as:

Developer Installs Malicious Provider → Go Malware Executes → System Reconnaissance → Slack Check-In → Blockchain C2 → Encrypted Commands → Go/JavaScript Execution

Once running, the malware collects information including:

  • Operating system
  • Hostname
  • Hardware information
  • Node.js availability

The information is transmitted to an attacker-controlled Slack channel through its API.

Blockchain and Slack Used for C2

The malware uses two unusual command-and-control mechanisms.

One channel uses a Slack bot token, while the second uses an Ethereum smart contract on the Arbitrum Sepolia testnet as a blockchain dead drop.

The implant periodically queries the smart contract for encrypted instructions. Commands intended for a particular infected machine can then be decrypted and executed as Go or JavaScript code.

The malware also generates an ephemeral public/private key pair and combines it with attacker-controlled public keys to establish shared encryption keys, helping separate communications between infected systems.

Possible Connection to Fake Job Interviews

Researchers noted similarities with the Graphalgo operation, in which developers were approached through LinkedIn, Facebook, forums and fake Web3 job opportunities.

Victims could be asked to complete coding assignments containing malicious dependencies, turning what appears to be a legitimate technical interview into an infection vector. Researchers have linked the broader Graphalgo activity to North Korea-associated threat actors, although they caution that it is still too early to conclude that Terraform registries have become a standard distribution method for those actors.

Why Terraform Providers Are Attractive Targets

Terraform commonly operates close to sensitive infrastructure and may have access to:

  • Cloud credentials
  • Environment variables
  • CI/CD secrets
  • Infrastructure APIs
  • Production configuration
  • Service-account credentials

A malicious provider executing inside such an environment could therefore provide attackers with a valuable foothold into infrastructure-management systems.

HashiCorp notes that providers downloaded from the registry are cryptographically signed, but community providers can be self-signed, and HashiCorp does not provide the same chain of trust for them as it does for HashiCorp-signed or verified partner providers.

What Security Teams Should Do

Organizations should check Terraform configurations, dependency lock files and developer environments for the identified packages.

Security teams should also:

  • Remove the malicious Terraform providers and Go modules.
  • Review terraform.lock.hcl for unexpected providers or versions.
  • Prefer official or verified providers where possible.
  • Pin provider versions rather than automatically accepting newer releases.
  • Review CI/CD environments for suspicious Terraform executions.
  • Investigate unexpected Slack API and blockchain RPC connections.
  • Rotate cloud or infrastructure credentials potentially exposed on affected systems.
  • Review developer systems involved in suspicious coding assignments or job interviews.

HashiCorp recommends constraining provider versions and committing Terraform's dependency lock file to version control so deployments consistently use expected provider releases.

Security Takeaway

This campaign demonstrates how software supply-chain attackers are expanding beyond traditional ecosystems such as npm and PyPI into Infrastructure-as-Code tooling.

Malicious Terraform Provider → Developer/CI Environment → Go Malware → Blockchain + Slack C2 → Remote Code Execution

The risk is particularly significant because Terraform often runs with access to sensitive cloud and production infrastructure credentials.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.