Sophia
Hart

Malicious Terraform Providers Deliver Go Malware via HashiCorp

Sophia Hart

Sep 24, 2026

6 min read

malicious terraform providers

TL; DR

  • Two Terraform providers and two Go modules on the HashiCorp Registry carried Go-based malware, the first confirmed use of this registry as a malware distribution vector.
  • The malware overlaps with Graphalgo, a campaign attributed to North Korean threat actors and first documented by ReversingLabs earlier in 2026.
  • The implant runs two separate command-and-control channels: a blockchain dead drop on the Arbitrum Sepolia testnet, and a Slack bot token.
  • The discovery coincides with newly flagged npm packages delivering the same malware family, alongside fake job-interview lures used to plant malicious dependencies in victims’ coding tasks.
  • A separate cluster, TraderTraitor, used weaponized Terraform lock files for unrelated Rust-based backdoors, but researchers say it is too early to call Terraform Registry abuse a confirmed new distribution pattern.

Attackers have used malicious Terraform providers to push Go-based malware through the HashiCorp Terraform Registry. Researchers at Aikido reported this as the first confirmed case of the centralized registry serving as a malware distribution channel. Two Terraform providers and two Go modules carried the payload.

The malware shares blockchain and Slack infrastructure with Graphalgo, a campaign that ReversingLabs first documented earlier this year and that researchers have tied to North Korean threat actors. The shift into infrastructure-as-code tooling matters operationally. Terraform providers execute during provisioning workflows, often on hosts that already hold cloud credentials, source access, and deployment secrets.

For DevOps and security teams, this changes where they need to review dependency risk. Code-review discipline built for application dependencies now needs to extend to infrastructure tooling.

Two Terraform providers and two Go modules carried the payload

Aikido identified four packages carrying the malware:

  • gocommunity-io/dockerd — Terraform provider, 222 downloads
  • kreuzwenker/docker — Terraform provider, 1,449 downloads. This is a typosquat of the legitimate kreuzwerker/docker provider, which has 56 million reported downloads. The two names differ by a single letter, ‘n’ in place of ‘r,’ the kind of mistake a developer makes when typing a provider name from memory.
  • gocommunity.io/orderedbtree — Go module, published August 11. Aikido found the malware shipped here in plaintext, with no encryption or compression to hide it.
  • gogets.dev/btreex — Go module, published September 8. This one hid its payload inside a ZIP archive disguised as a SQL file. The threat actor also forged commit history, backdating it to November 2025 to make the package look more established than it was.

Terraform providers run as plugins during infrastructure provisioning. That execution context often includes cloud credentials, repository access, and CI secrets. A malicious provider therefore reaches privileged material more directly than a typical application dependency does. Aikido noted the campaign is also expanding its reach beyond npm and PyPI, the ecosystems where this malware family first appeared.

Two separate communication channels, not one

The Go version of the malware, ported from the npm implant, retains its dual command-and-control design. These are two distinct mechanisms, and reviewed sources describe them separately.

Before either channel activates, the malware stays inert. In the Terraform providers, the malicious code is hidden inside resource_docker_container_funcs.go and only runs when the SHA256 hash of the containerName and networkID input variables, concatenated together, matches a hardcoded value. Without that exact match, the payload never executes. This is why automated sandbox analysis, which typically runs generic or randomized test inputs, missed the malware. The sandbox simply never supplied the specific values needed to trigger it.

Blockchain dead drop

The malware polls a hard-coded Ethereum smart contract on the Arbitrum Sepolia testnet every three seconds for encrypted commands. Researcher Oliver Smith said the malware generates an ephemeral key pair, then combines it with two threat-actor public keys to derive shared keys. This lets infected hosts communicate without exposing C2 traffic to other infected clients. Commands execute as Go or JavaScript.

Slack side channel

The implant separately polls Slack’s conversations.history endpoint every 10 seconds using a bot token. It reads packet types (start, chunk, end) to reassemble file transfers delivered over Slack.

Socket researcher Karlo Zanki said execution appears gated by data supplied through a front-end component, which likely hinders analysis rather than indicating narrow targeting alone.

Part of a broader, still-forming pattern

Developers are lured via fake job offers, overlapping with Contagious Interview tactics. TraderTraitor separately used weaponized Terraform lock files for different Rust backdoors. Researchers call this pattern still unconfirmed.

Compromised packages at a glance

Package Type Operational Priority
kreuzwenker/docker Terraform provider (1,449 downloads) Highest exposure; audit every pipeline that pulled this provider
gocommunity-io/dockerd Terraform provider (222 downloads) Confirm removal from any Terraform configuration referencing it
gocommunity.io/orderedbtree Go module Review dependent Go projects for inclusion
gogets.dev/btreex Go module Review dependent Go projects for inclusion

Where endpoint controls fit in

Terraform providers and Go modules run directly on developer and DevOps endpoints, so endpoint-level controls still have a role to play. Here’s what Hexnode UEM and XDR can and can’t do in this scenario.

Hexnode UEM

  • Application blocklisting and allowlisting  – Available on Windows, macOS, Linux, iOS, Android, tvOS, and Fire OS endpoints. Lets administrators restrict unapproved development tools on developer machines.
  • Non-compliance flagging – Hexnode UEM flags devices where blocklisted software appears, giving admins a signal to investigate.

Hexnode XDR

  • Windows and macOS coverage – Hexnode XDR can investigate suspicious activity on managed Windows and macOS endpoints, giving security teams a starting point for containment on those platforms.
  • Scope limit – This is endpoint-level investigation, not detection of a specific malware family or implant.

What Hexnode does not cover:

  • Detecting this specific malware family or the Graphalgo implant
  • Patching the compromised Terraform providers or Go modules
  • Monitoring CI/CD pipeline logs, registry activity, or blockchain traffic

Book a free demo and explore Hexnode today!
Endpoint controls complement, but don’t replace, the credential rotation, dependency review, and registry-level scrutiny that affected teams and HashiCorp itself must handle directly.

FAQs

No. Reviewed sources describe attackers publishing malicious packages under their own namespaces, not compromising the registry’s infrastructure.

Terraform providers execute during infrastructure provisioning, often with direct access to cloud credentials and deployment permissions that standard application dependencies don’t carry.

Not necessarily. Verify publisher identity, pin exact versions, and review what credentials a provider’s execution context can reach before adopting it.

cybersecurity framework

Building a cybersecurity framework for your enterprise

Explore key cybersecurity frameworks and how UEM strengthens organizational defenses against network penetration attacks.

DOWNLOAD

Conclusion

This campaign shows that infrastructure-as-code dependencies now sit inside the same trust boundary as production code. A malicious Terraform provider can reach cloud credentials and deployment privileges that most application dependencies never touch.

Security teams should treat unfamiliar or low-adoption Terraform providers and Go modules with the same scrutiny applied to production code, and extend endpoint and credential hygiene to developer and CI/CD environments accordingly.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.